U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2009-3129

Change History

Modified Analysis by NIST 7/16/2024 1:18:57 PM

Action Type Old Value New Value
Changed CPE Configuration
OR
     *cpe:2.3:a:microsoft:compatibility_pack_word_excel_powerpoint:2007:sp1:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:compatibility_pack_word_excel_powerpoint:2007:sp2:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:excel:2003:sp3:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:excel:2007:sp1:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:excel:2007:sp2:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:excel_viewer:*:sp1:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:excel_viewer:*:sp2:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:excel_viewer:2003:sp3:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*
     *cpe:2.3:a:microsoft:office:2008:*:mac:*:*:*:*:*
     *cpe:2.3:a:microsoft:open_xml_file_format_converter:*:*:mac:*:*:*:*:*
OR
     *cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:excel:2003:sp3:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:excel:2007:sp1:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:excel:2007:sp2:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:excel_viewer:-:sp1:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:excel_viewer:-:sp2:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:excel_viewer:2003:sp3:*:*:*:*:*:*
     *cpe:2.3:a:microsoft:office:2004:*:*:*:*:macos:*:*
     *cpe:2.3:a:microsoft:office:2008:*:*:*:*:macos:*:*
     *cpe:2.3:a:microsoft:open_xml_file_format_converter:*:*:*:*:*:macos:*:*
Added CVSS V3.1

								
							
							
						
NIST AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
NIST CWE-787
Removed CWE
NIST CWE-94

								
						
Changed Reference Type
http://archives.neohapsis.com/archives/bugtraq/2009-11/0080.html No Types Assigned
http://archives.neohapsis.com/archives/bugtraq/2009-11/0080.html Broken Link
Changed Reference Type
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=832 No Types Assigned
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=832 Broken Link
Changed Reference Type
http://osvdb.org/59860 No Types Assigned
http://osvdb.org/59860 Broken Link
Changed Reference Type
http://www.exploit-db.com/exploits/14706 Exploit
http://www.exploit-db.com/exploits/14706 Exploit, Third Party Advisory, VDB Entry
Changed Reference Type
http://www.securityfocus.com/bid/36945 No Types Assigned
http://www.securityfocus.com/bid/36945 Broken Link, Third Party Advisory, VDB Entry
Changed Reference Type
http://www.securitytracker.com/id?1023157 No Types Assigned
http://www.securitytracker.com/id?1023157 Broken Link, Third Party Advisory, VDB Entry
Changed Reference Type
http://www.us-cert.gov/cas/techalerts/TA09-314A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA09-314A.html Third Party Advisory, US Government Resource
Changed Reference Type
http://www.zerodayinitiative.com/advisories/ZDI-09-083 No Types Assigned
http://www.zerodayinitiative.com/advisories/ZDI-09-083 Third Party Advisory, VDB Entry
Changed Reference Type
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-067 No Types Assigned
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-067 Patch, Vendor Advisory
Changed Reference Type
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6521 No Types Assigned
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6521 Broken Link