VYPR
Unrated severityNVD Advisory· Published Nov 11, 2009· Updated Jun 16, 2026

CVE-2009-3130

CVE-2009-3130

Description

Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a spreadsheet containing a malformed Binary File Format (aka BIFF) record that triggers memory corruption, aka "Excel Document Parsing Heap Overflow Vulnerability."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

14
  • cpe:2.3:a:microsoft:compatibility_pack_word_excel_powerpoint:2007:sp1:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:compatibility_pack_word_excel_powerpoint:2007:sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:compatibility_pack_word_excel_powerpoint:2007:sp2:*:*:*:*:*:*
  • Microsoft/Excel4 versions
    cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:excel:2003:sp3:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:excel:2007:sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:excel:2007:sp2:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:excel_viewer:2003:sp3:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:microsoft:excel_viewer:2003:sp3:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:excel_viewer:*:sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:excel_viewer:*:sp2:*:*:*:*:*:*
  • Microsoft/Office2 versions
    cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2008:*:mac:*:*:*:*:*
  • cpe:2.3:a:microsoft:open_xml_file_format_converter:*:*:mac:*:*:*:*:*
  • Range: =2004
  • Range: =2002 SP3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.