VYPR
Unrated severityNVD Advisory· Published Aug 12, 2008· Updated Jun 16, 2026

CVE-2008-3021

CVE-2008-3021

Description

Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file with an invalid bits_per_pixel field, aka the "PICT Filter Parsing Vulnerability," a different vulnerability than CVE-2008-3018.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • Microsoft/Office3 versions
    cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:office_converter_pack:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:office_converter_pack:*:*:*:*:*:*:*:*
    • (no CPE)
  • Microsoft/Works2 versions
    cpe:2.3:a:microsoft:works:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:works:8.0:*:*:*:*:*:*:*
    • (no CPE)range: 8
  • Range: SP2
  • Range: SP3
  • Range: SP3

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.