CyberSec.Space Logo
Back to CVE Browser

CVE-2008-3460

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.1510%
EPSS Percentile32.05th
PublishedAug 12, 2008
Last ModifiedApr 23, 2026

Vulnerability Description

WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 does not properly parse the length of a WordPerfect Graphics (WPG) file, which allows remote attackers to execute arbitrary code via a crafted WPG file, aka the "WPG Image File Heap Corruption Vulnerability."

Affected Platforms (CPE)

πŸ“¦
Microsoft

Office

= 2000
πŸ“¦
Microsoft

Office

= 2003
πŸ“¦
Microsoft

Office

= xp
πŸ“¦
Microsoft

Office Converter Pack

All versions
πŸ“¦
Microsoft

Works

= 8.0

References & Advisories

Related Vulnerabilities