AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-0220

HIGH · CVSS 9.3 EPSS 37.11%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-05-12 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-0220
Severity
HIGH
CVSS
9.3
EPSS
37.11%
Microsoft Office

Original NVD Description

Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via crafted formatting data for paragraphs in a file that uses a PowerPoint 4.0 native file format, related to (1) an incorrect calculation from a record header, or (2) an interget that is used to specify the number of bytes to copy, aka "Legacy File Format Vulnerability."