← Vulnerability feed

Vulnerability record · CVE-2002-1338 · published 18 December 2002

CVE-2002-1338: Microsoft office web components vulnerability

Microsoft · Office Web Components

The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of local files.

5.0 CVSS 2.0 Medium EPSS 23% · top 2.3%
5.0CVSS 2.0 base score
23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of local files.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1338 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed8.8CVE-2012-0158Microsoft MSCOMCTL.OCX ActiveX controls remote code executionThe ListView, ListView2, TreeView and TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls fail to handle crafted input, allowing memory…KEVEPSS 100%analysed9.3CVE-2009-0562Microsoft isa server vulnerabilityThe Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, …EPSS 26%9.3CVE-2009-1534Microsoft Office Web Components ActiveX control buffer overflowThe Office Web Components ActiveX control contains a buffer overflow that is triggered by crafted property values. Because the control is loaded in t…EPSS 52%analysed9.3CVE-2009-2496Microsoft biztalk server memory buffer overflow vulnerabilityHeap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Of…EPSS 29%9.3CVE-2009-1136Microsoft Office Web Components ActiveX control remote code executionThe Microsoft Office Web Components Spreadsheet ActiveX control (OWC10/OWC11) can be abused through a crafted call to the msDataSourceObject method w…EPSS 62%analysed9.3CVE-2006-4695Microsoft office web components code injection vulnerabilityUnspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary c…EPSS 40%7.5CVE-2002-0727Microsoft office web components vulnerabilityThe Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2002-1338), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.