Search

Find a vulnerability

Search criteria

    61 vulnerabilities by OpenOffice

    CERTFR-2025-AVI-0992

    Vulnerability from certfr_avis - Published: 2025-11-12 - Updated: 2025-11-12

    De multiples vulnérabilités ont été découvertes dans Apache OpenOffice. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    OpenOffice OpenOffice OpenOffice versions antérieures à 4.1.16
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "OpenOffice versions ant\u00e9rieures \u00e0 4.1.16",
          "product": {
            "name": "OpenOffice",
            "vendor": {
              "name": "OpenOffice",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-64403",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64403"
        },
        {
          "name": "CVE-2025-64402",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64402"
        },
        {
          "name": "CVE-2023-2255",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-2255"
        },
        {
          "name": "CVE-2024-12426",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-12426"
        },
        {
          "name": "CVE-2025-64407",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64407"
        },
        {
          "name": "CVE-2025-64406",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64406"
        },
        {
          "name": "CVE-2025-64401",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64401"
        },
        {
          "name": "CVE-2025-64404",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64404"
        },
        {
          "name": "CVE-2025-64405",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-64405"
        }
      ],
      "initial_release_date": "2025-11-12T00:00:00",
      "last_revision_date": "2025-11-12T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0992",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-11-12T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Apache OpenOffice. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans Apache OpenOffice",
      "vendor_advisories": [
        {
          "published_at": "2025-11-12",
          "title": "Bulletin de s\u00e9curit\u00e9 OpenOffice CVE-2025-64404",
          "url": "https://www.openoffice.org/security/cves/CVE-2025-64404.html"
        },
        {
          "published_at": "2025-11-12",
          "title": "Bulletin de s\u00e9curit\u00e9 OpenOffice CVE-2025-64402",
          "url": "https://www.openoffice.org/security/cves/CVE-2025-64402.html"
        },
        {
          "published_at": "2025-11-12",
          "title": "Bulletin de s\u00e9curit\u00e9 OpenOffice CVE-2025-64406",
          "url": "https://www.openoffice.org/security/cves/CVE-2025-64406.html"
        },
        {
          "published_at": "2025-11-12",
          "title": "Bulletin de s\u00e9curit\u00e9 OpenOffice CVE-2025-64403",
          "url": "https://www.openoffice.org/security/cves/CVE-2025-64403.html"
        },
        {
          "published_at": "2025-11-12",
          "title": "Bulletin de s\u00e9curit\u00e9 OpenOffice CVE-2025-64401",
          "url": "https://www.openoffice.org/security/cves/CVE-2025-64401.html"
        },
        {
          "published_at": "2025-11-12",
          "title": "Bulletin de s\u00e9curit\u00e9 OpenOffice CVE-2025-64405",
          "url": "https://www.openoffice.org/security/cves/CVE-2025-64405.html"
        },
        {
          "published_at": "2025-11-12",
          "title": "Bulletin de s\u00e9curit\u00e9 OpenOffice CVE-2025-64407",
          "url": "https://www.openoffice.org/security/cves/CVE-2025-64407.html"
        }
      ]
    }

    CVE-2010-2936 (GCVE-0-2010-2936)

    Vulnerability from nvd – Published: 2010-08-25 19:00 – Updated: 2024-08-07 02:46
    VLAI
    Summary
    Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://secunia.com/advisories/40775 third-party-advisoryx_refsource_SECUNIA
    http://www.openoffice.org/servlets/ReadMsg?list=d… mailing-listx_refsource_MLIST
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.vupen.com/english/advisories/2010/2003 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/60799 third-party-advisoryx_refsource_SECUNIA
    http://www.securitytracker.com/id?1024976 vdb-entryx_refsource_SECTRACK
    http://www.gentoo.org/security/en/glsa/glsa-20140… vendor-advisoryx_refsource_GENTOO
    http://www.vupen.com/english/advisories/2011/0150 vdb-entryx_refsource_VUPEN
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://secunia.com/advisories/42927 third-party-advisoryx_refsource_SECUNIA
    http://www.redhat.com/support/errata/RHSA-2010-06… vendor-advisoryx_refsource_REDHAT
    http://www.vupen.com/english/advisories/2011/0230 vdb-entryx_refsource_VUPEN
    http://www.vupen.com/english/advisories/2010/2149 vdb-entryx_refsource_VUPEN
    http://www.openwall.com/lists/oss-security/2010/08/11/1 mailing-listx_refsource_MLIST
    http://www.vupen.com/english/advisories/2010/2228 vdb-entryx_refsource_VUPEN
    http://www.openoffice.org/security/cves/CVE-2010-… x_refsource_CONFIRM
    https://bugzilla.redhat.com/show_bug.cgi?id=622529#c6 x_refsource_CONFIRM
    http://secunia.com/advisories/41235 third-party-advisoryx_refsource_SECUNIA
    http://ubuntu.com/usn/usn-1056-1 vendor-advisoryx_refsource_UBUNTU
    https://bugzilla.redhat.com/show_bug.cgi?id=622555 x_refsource_CONFIRM
    http://www.vupen.com/english/advisories/2011/0279 vdb-entryx_refsource_VUPEN
    http://www.securitytracker.com/id?1024352 vdb-entryx_refsource_SECTRACK
    http://secunia.com/advisories/43105 third-party-advisoryx_refsource_SECUNIA
    http://securityevaluators.com/files/papers/CrashA… x_refsource_MISC
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.debian.org/security/2010/dsa-2099 vendor-advisoryx_refsource_DEBIAN
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.oracle.com/technetwork/topics/security… x_refsource_CONFIRM
    http://secunia.com/advisories/41052 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2010/2905 vdb-entryx_refsource_VUPEN
    http://www.openwall.com/lists/oss-security/2010/08/11/4 mailing-listx_refsource_MLIST
    Date Public
    2010-08-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T02:46:48.696Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "40775",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/40775"
              },
              {
                "name": "[dev] 20100806 Two exploitable OpenOffice.org bugs!",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/servlets/ReadMsg?list=dev\u0026msgNo=27690"
              },
              {
                "name": "MDVSA-2010:221",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:221"
              },
              {
                "name": "ADV-2010-2003",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2003"
              },
              {
                "name": "60799",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/60799"
              },
              {
                "name": "1024976",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1024976"
              },
              {
                "name": "GLSA-201408-19",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
              },
              {
                "name": "ADV-2011-0150",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0150"
              },
              {
                "name": "oval:org.mitre.oval:def:12144",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12144"
              },
              {
                "name": "42927",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/42927"
              },
              {
                "name": "RHSA-2010:0643",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2010-0643.html"
              },
              {
                "name": "ADV-2011-0230",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0230"
              },
              {
                "name": "ADV-2010-2149",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2149"
              },
              {
                "name": "[oss-security] 20100811 CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2010/08/11/1"
              },
              {
                "name": "ADV-2010-2228",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2228"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2010-2935_CVE-2010-2936.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=622529#c6"
              },
              {
                "name": "41235",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/41235"
              },
              {
                "name": "USN-1056-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://ubuntu.com/usn/usn-1056-1"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=622555"
              },
              {
                "name": "ADV-2011-0279",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0279"
              },
              {
                "name": "1024352",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1024352"
              },
              {
                "name": "43105",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/43105"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://securityevaluators.com/files/papers/CrashAnalysis.pdf"
              },
              {
                "name": "SUSE-SR:2010:024",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html"
              },
              {
                "name": "DSA-2099",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2010/dsa-2099"
              },
              {
                "name": "SUSE-SR:2010:019",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html"
              },
              {
                "name": "41052",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/41052"
              },
              {
                "name": "ADV-2010-2905",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2905"
              },
              {
                "name": "[oss-security] 20100811 Re: CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2010/08/11/4"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2010-08-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-18T12:57:01.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "name": "40775",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/40775"
            },
            {
              "name": "[dev] 20100806 Two exploitable OpenOffice.org bugs!",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openoffice.org/servlets/ReadMsg?list=dev\u0026msgNo=27690"
            },
            {
              "name": "MDVSA-2010:221",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:221"
            },
            {
              "name": "ADV-2010-2003",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2003"
            },
            {
              "name": "60799",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/60799"
            },
            {
              "name": "1024976",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1024976"
            },
            {
              "name": "GLSA-201408-19",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
            },
            {
              "name": "ADV-2011-0150",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0150"
            },
            {
              "name": "oval:org.mitre.oval:def:12144",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12144"
            },
            {
              "name": "42927",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/42927"
            },
            {
              "name": "RHSA-2010:0643",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2010-0643.html"
            },
            {
              "name": "ADV-2011-0230",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0230"
            },
            {
              "name": "ADV-2010-2149",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2149"
            },
            {
              "name": "[oss-security] 20100811 CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2010/08/11/1"
            },
            {
              "name": "ADV-2010-2228",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2228"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2010-2935_CVE-2010-2936.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=622529#c6"
            },
            {
              "name": "41235",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/41235"
            },
            {
              "name": "USN-1056-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://ubuntu.com/usn/usn-1056-1"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=622555"
            },
            {
              "name": "ADV-2011-0279",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0279"
            },
            {
              "name": "1024352",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1024352"
            },
            {
              "name": "43105",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/43105"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://securityevaluators.com/files/papers/CrashAnalysis.pdf"
            },
            {
              "name": "SUSE-SR:2010:024",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html"
            },
            {
              "name": "DSA-2099",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2010/dsa-2099"
            },
            {
              "name": "SUSE-SR:2010:019",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html"
            },
            {
              "name": "41052",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/41052"
            },
            {
              "name": "ADV-2010-2905",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2905"
            },
            {
              "name": "[oss-security] 20100811 Re: CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2010/08/11/4"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2010-2936",
        "datePublished": "2010-08-25T19:00:00.000Z",
        "dateReserved": "2010-08-04T00:00:00.000Z",
        "dateUpdated": "2024-08-07T02:46:48.696Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2010-2935 (GCVE-0-2010-2935)

    Vulnerability from nvd – Published: 2010-08-25 19:00 – Updated: 2024-08-07 02:46
    VLAI
    Summary
    simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an "integer truncation error."
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://secunia.com/advisories/40775 third-party-advisoryx_refsource_SECUNIA
    http://www.openoffice.org/servlets/ReadMsg?list=d… mailing-listx_refsource_MLIST
    https://bugzilla.redhat.com/show_bug.cgi?id=622529 x_refsource_CONFIRM
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.vupen.com/english/advisories/2010/2003 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/60799 third-party-advisoryx_refsource_SECUNIA
    http://www.securitytracker.com/id?1024976 vdb-entryx_refsource_SECTRACK
    http://www.gentoo.org/security/en/glsa/glsa-20140… vendor-advisoryx_refsource_GENTOO
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.vupen.com/english/advisories/2011/0150 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/42927 third-party-advisoryx_refsource_SECUNIA
    http://www.redhat.com/support/errata/RHSA-2010-06… vendor-advisoryx_refsource_REDHAT
    http://www.vupen.com/english/advisories/2011/0230 vdb-entryx_refsource_VUPEN
    http://www.vupen.com/english/advisories/2010/2149 vdb-entryx_refsource_VUPEN
    http://www.openwall.com/lists/oss-security/2010/08/11/1 mailing-listx_refsource_MLIST
    http://www.vupen.com/english/advisories/2010/2228 vdb-entryx_refsource_VUPEN
    http://www.openoffice.org/security/cves/CVE-2010-… x_refsource_CONFIRM
    http://secunia.com/advisories/41235 third-party-advisoryx_refsource_SECUNIA
    http://ubuntu.com/usn/usn-1056-1 vendor-advisoryx_refsource_UBUNTU
    http://www.vupen.com/english/advisories/2011/0279 vdb-entryx_refsource_VUPEN
    http://www.securitytracker.com/id?1024352 vdb-entryx_refsource_SECTRACK
    http://secunia.com/advisories/43105 third-party-advisoryx_refsource_SECUNIA
    http://securityevaluators.com/files/papers/CrashA… x_refsource_MISC
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.debian.org/security/2010/dsa-2099 vendor-advisoryx_refsource_DEBIAN
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.oracle.com/technetwork/topics/security… x_refsource_CONFIRM
    http://secunia.com/advisories/41052 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2010/2905 vdb-entryx_refsource_VUPEN
    http://www.openwall.com/lists/oss-security/2010/08/11/4 mailing-listx_refsource_MLIST
    Date Public
    2010-08-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T02:46:48.941Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "40775",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/40775"
              },
              {
                "name": "[dev] 20100806 Two exploitable OpenOffice.org bugs!",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/servlets/ReadMsg?list=dev\u0026msgNo=27690"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=622529"
              },
              {
                "name": "MDVSA-2010:221",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:221"
              },
              {
                "name": "ADV-2010-2003",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2003"
              },
              {
                "name": "60799",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/60799"
              },
              {
                "name": "1024976",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1024976"
              },
              {
                "name": "GLSA-201408-19",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
              },
              {
                "name": "oval:org.mitre.oval:def:12063",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12063"
              },
              {
                "name": "ADV-2011-0150",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0150"
              },
              {
                "name": "42927",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/42927"
              },
              {
                "name": "RHSA-2010:0643",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2010-0643.html"
              },
              {
                "name": "ADV-2011-0230",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0230"
              },
              {
                "name": "ADV-2010-2149",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2149"
              },
              {
                "name": "[oss-security] 20100811 CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2010/08/11/1"
              },
              {
                "name": "ADV-2010-2228",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2228"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2010-2935_CVE-2010-2936.html"
              },
              {
                "name": "41235",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/41235"
              },
              {
                "name": "USN-1056-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://ubuntu.com/usn/usn-1056-1"
              },
              {
                "name": "ADV-2011-0279",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0279"
              },
              {
                "name": "1024352",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1024352"
              },
              {
                "name": "43105",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/43105"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://securityevaluators.com/files/papers/CrashAnalysis.pdf"
              },
              {
                "name": "SUSE-SR:2010:024",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html"
              },
              {
                "name": "DSA-2099",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2010/dsa-2099"
              },
              {
                "name": "SUSE-SR:2010:019",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html"
              },
              {
                "name": "41052",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/41052"
              },
              {
                "name": "ADV-2010-2905",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2905"
              },
              {
                "name": "[oss-security] 20100811 Re: CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2010/08/11/4"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2010-08-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an \"integer truncation error.\""
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-18T12:57:01.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "name": "40775",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/40775"
            },
            {
              "name": "[dev] 20100806 Two exploitable OpenOffice.org bugs!",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openoffice.org/servlets/ReadMsg?list=dev\u0026msgNo=27690"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=622529"
            },
            {
              "name": "MDVSA-2010:221",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:221"
            },
            {
              "name": "ADV-2010-2003",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2003"
            },
            {
              "name": "60799",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/60799"
            },
            {
              "name": "1024976",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1024976"
            },
            {
              "name": "GLSA-201408-19",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
            },
            {
              "name": "oval:org.mitre.oval:def:12063",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12063"
            },
            {
              "name": "ADV-2011-0150",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0150"
            },
            {
              "name": "42927",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/42927"
            },
            {
              "name": "RHSA-2010:0643",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2010-0643.html"
            },
            {
              "name": "ADV-2011-0230",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0230"
            },
            {
              "name": "ADV-2010-2149",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2149"
            },
            {
              "name": "[oss-security] 20100811 CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2010/08/11/1"
            },
            {
              "name": "ADV-2010-2228",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2228"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2010-2935_CVE-2010-2936.html"
            },
            {
              "name": "41235",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/41235"
            },
            {
              "name": "USN-1056-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://ubuntu.com/usn/usn-1056-1"
            },
            {
              "name": "ADV-2011-0279",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0279"
            },
            {
              "name": "1024352",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1024352"
            },
            {
              "name": "43105",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/43105"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://securityevaluators.com/files/papers/CrashAnalysis.pdf"
            },
            {
              "name": "SUSE-SR:2010:024",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html"
            },
            {
              "name": "DSA-2099",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2010/dsa-2099"
            },
            {
              "name": "SUSE-SR:2010:019",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html"
            },
            {
              "name": "41052",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/41052"
            },
            {
              "name": "ADV-2010-2905",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2905"
            },
            {
              "name": "[oss-security] 20100811 Re: CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2010/08/11/4"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2010-2935",
        "datePublished": "2010-08-25T19:00:00.000Z",
        "dateReserved": "2010-08-04T00:00:00.000Z",
        "dateUpdated": "2024-08-07T02:46:48.941Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-3571 (GCVE-0-2009-3571)

    Vulnerability from nvd – Published: 2009-10-06 20:19 – Updated: 2024-08-07 06:31
    VLAI
    Summary
    Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side exploit." NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.securityfocus.com/bid/36285 vdb-entryx_refsource_BID
    http://www.securitytracker.com/id?1022832 vdb-entryx_refsource_SECTRACK
    http://secunia.com/advisories/35036 third-party-advisoryx_refsource_SECUNIA
    http://intevydis.com/vd-list.shtml x_refsource_MISC
    Date Public
    2009-09-04 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T06:31:10.630Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "36285",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/36285"
              },
              {
                "name": "1022832",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1022832"
              },
              {
                "name": "35036",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/35036"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://intevydis.com/vd-list.shtml"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-09-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka \"Client-side exploit.\" NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2014-10-20T13:57:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "36285",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/36285"
            },
            {
              "name": "1022832",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1022832"
            },
            {
              "name": "35036",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/35036"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://intevydis.com/vd-list.shtml"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2009-3571",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka \"Client-side exploit.\" NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "36285",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/36285"
                },
                {
                  "name": "1022832",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1022832"
                },
                {
                  "name": "35036",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/35036"
                },
                {
                  "name": "http://intevydis.com/vd-list.shtml",
                  "refsource": "MISC",
                  "url": "http://intevydis.com/vd-list.shtml"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2009-3571",
        "datePublished": "2009-10-06T20:19:00.000Z",
        "dateReserved": "2009-10-06T00:00:00.000Z",
        "dateUpdated": "2024-08-07T06:31:10.630Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-3570 (GCVE-0-2009-3570)

    Vulnerability from nvd – Published: 2009-10-06 20:19 – Updated: 2024-08-07 06:31
    VLAI
    Summary
    Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9. NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.securityfocus.com/bid/36285 vdb-entryx_refsource_BID
    http://secunia.com/advisories/35036 third-party-advisoryx_refsource_SECUNIA
    http://www.securitytracker.com/id?1022828 vdb-entryx_refsource_SECTRACK
    http://intevydis.com/vd-list.shtml x_refsource_MISC
    Date Public
    2009-09-04 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T06:31:10.433Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "36285",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/36285"
              },
              {
                "name": "35036",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/35036"
              },
              {
                "name": "1022828",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1022828"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://intevydis.com/vd-list.shtml"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-09-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9.  NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2014-10-20T13:57:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "36285",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/36285"
            },
            {
              "name": "35036",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/35036"
            },
            {
              "name": "1022828",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1022828"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://intevydis.com/vd-list.shtml"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2009-3570",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9.  NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "36285",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/36285"
                },
                {
                  "name": "35036",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/35036"
                },
                {
                  "name": "1022828",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1022828"
                },
                {
                  "name": "http://intevydis.com/vd-list.shtml",
                  "refsource": "MISC",
                  "url": "http://intevydis.com/vd-list.shtml"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2009-3570",
        "datePublished": "2009-10-06T20:19:00.000Z",
        "dateReserved": "2009-10-06T00:00:00.000Z",
        "dateUpdated": "2024-08-07T06:31:10.433Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-0201 (GCVE-0-2009-0201)

    Vulnerability from nvd – Published: 2009-09-02 17:00 – Updated: 2024-08-07 04:24
    VLAI
    Summary
    Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to "table parsing."
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.openoffice.org/security/cves/CVE-2009-… x_refsource_CONFIRM
    http://secunia.com/advisories/60799 third-party-advisoryx_refsource_SECUNIA
    http://www.gentoo.org/security/en/glsa/glsa-20140… vendor-advisoryx_refsource_GENTOO
    http://development.openoffice.org/releases/3.1.1.html x_refsource_MISC
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.securitytracker.com/id?1022798 vdb-entryx_refsource_SECTRACK
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://www.securityfocus.com/archive/1/506195/100… mailing-listx_refsource_BUGTRAQ
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.debian.org/security/2009/dsa-1880 vendor-advisoryx_refsource_DEBIAN
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://secunia.com/secunia_research/2009-27/ x_refsource_MISC
    http://secunia.com/advisories/35036 third-party-advisoryx_refsource_SECUNIA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/36750 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/bid/36200 vdb-entryx_refsource_BID
    http://www.vupen.com/english/advisories/2009/2490 vdb-entryx_refsource_VUPEN
    Date Public
    2009-09-01 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T04:24:18.137Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html"
              },
              {
                "name": "60799",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/60799"
              },
              {
                "name": "GLSA-201408-19",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://development.openoffice.org/releases/3.1.1.html"
              },
              {
                "name": "MDVSA-2010:105",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:105"
              },
              {
                "name": "1022798",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1022798"
              },
              {
                "name": "MDVSA-2010:091",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:091"
              },
              {
                "name": "MDVSA-2010:035",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:035"
              },
              {
                "name": "1020715",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1"
              },
              {
                "name": "20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Buffer Overflow",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/506195/100/0/threaded"
              },
              {
                "name": "SUSE-SR:2009:015",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"
              },
              {
                "name": "DSA-1880",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2009/dsa-1880"
              },
              {
                "name": "oval:org.mitre.oval:def:10726",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10726"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://secunia.com/secunia_research/2009-27/"
              },
              {
                "name": "35036",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/35036"
              },
              {
                "name": "263508",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1"
              },
              {
                "name": "36750",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/36750"
              },
              {
                "name": "36200",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/36200"
              },
              {
                "name": "ADV-2009-2490",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2009/2490"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-09-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to \"table parsing.\""
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-11T19:57:01.000Z",
            "orgId": "44d08088-2bea-4760-83a6-1e9be26b15ab",
            "shortName": "flexera"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html"
            },
            {
              "name": "60799",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/60799"
            },
            {
              "name": "GLSA-201408-19",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://development.openoffice.org/releases/3.1.1.html"
            },
            {
              "name": "MDVSA-2010:105",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:105"
            },
            {
              "name": "1022798",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1022798"
            },
            {
              "name": "MDVSA-2010:091",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:091"
            },
            {
              "name": "MDVSA-2010:035",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:035"
            },
            {
              "name": "1020715",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1"
            },
            {
              "name": "20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Buffer Overflow",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/506195/100/0/threaded"
            },
            {
              "name": "SUSE-SR:2009:015",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"
            },
            {
              "name": "DSA-1880",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2009/dsa-1880"
            },
            {
              "name": "oval:org.mitre.oval:def:10726",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10726"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://secunia.com/secunia_research/2009-27/"
            },
            {
              "name": "35036",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/35036"
            },
            {
              "name": "263508",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1"
            },
            {
              "name": "36750",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/36750"
            },
            {
              "name": "36200",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/36200"
            },
            {
              "name": "ADV-2009-2490",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2009/2490"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "PSIRT-CNA@flexerasoftware.com",
              "ID": "CVE-2009-0201",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to \"table parsing.\""
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html"
                },
                {
                  "name": "60799",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/60799"
                },
                {
                  "name": "GLSA-201408-19",
                  "refsource": "GENTOO",
                  "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
                },
                {
                  "name": "http://development.openoffice.org/releases/3.1.1.html",
                  "refsource": "MISC",
                  "url": "http://development.openoffice.org/releases/3.1.1.html"
                },
                {
                  "name": "MDVSA-2010:105",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:105"
                },
                {
                  "name": "1022798",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1022798"
                },
                {
                  "name": "MDVSA-2010:091",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:091"
                },
                {
                  "name": "MDVSA-2010:035",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:035"
                },
                {
                  "name": "1020715",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1"
                },
                {
                  "name": "20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Buffer Overflow",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/506195/100/0/threaded"
                },
                {
                  "name": "SUSE-SR:2009:015",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"
                },
                {
                  "name": "DSA-1880",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2009/dsa-1880"
                },
                {
                  "name": "oval:org.mitre.oval:def:10726",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10726"
                },
                {
                  "name": "http://secunia.com/secunia_research/2009-27/",
                  "refsource": "MISC",
                  "url": "http://secunia.com/secunia_research/2009-27/"
                },
                {
                  "name": "35036",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/35036"
                },
                {
                  "name": "263508",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1"
                },
                {
                  "name": "36750",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/36750"
                },
                {
                  "name": "36200",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/36200"
                },
                {
                  "name": "ADV-2009-2490",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2009/2490"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "44d08088-2bea-4760-83a6-1e9be26b15ab",
        "assignerShortName": "flexera",
        "cveId": "CVE-2009-0201",
        "datePublished": "2009-09-02T17:00:00.000Z",
        "dateReserved": "2009-01-20T00:00:00.000Z",
        "dateUpdated": "2024-08-07T04:24:18.137Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-0200 (GCVE-0-2009-0200)

    Vulnerability from nvd – Published: 2009-09-02 17:00 – Updated: 2024-08-07 04:24
    VLAI
    Summary
    Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.openoffice.org/security/cves/CVE-2009-… x_refsource_CONFIRM
    http://secunia.com/advisories/60799 third-party-advisoryx_refsource_SECUNIA
    http://www.gentoo.org/security/en/glsa/glsa-20140… vendor-advisoryx_refsource_GENTOO
    http://development.openoffice.org/releases/3.1.1.html x_refsource_MISC
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://secunia.com/secunia_research/2009-26/ x_refsource_MISC
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.debian.org/security/2009/dsa-1880 vendor-advisoryx_refsource_DEBIAN
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://secunia.com/advisories/35036 third-party-advisoryx_refsource_SECUNIA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/36750 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/archive/1/506194/100… mailing-listx_refsource_BUGTRAQ
    http://www.securityfocus.com/bid/36200 vdb-entryx_refsource_BID
    http://www.vupen.com/english/advisories/2009/2490 vdb-entryx_refsource_VUPEN
    Date Public
    2009-09-01 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T04:24:18.284Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html"
              },
              {
                "name": "60799",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/60799"
              },
              {
                "name": "GLSA-201408-19",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://development.openoffice.org/releases/3.1.1.html"
              },
              {
                "name": "MDVSA-2010:105",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:105"
              },
              {
                "name": "MDVSA-2010:091",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:091"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://secunia.com/secunia_research/2009-26/"
              },
              {
                "name": "MDVSA-2010:035",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:035"
              },
              {
                "name": "1020715",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1"
              },
              {
                "name": "SUSE-SR:2009:015",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"
              },
              {
                "name": "DSA-1880",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2009/dsa-1880"
              },
              {
                "name": "oval:org.mitre.oval:def:10881",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10881"
              },
              {
                "name": "35036",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/35036"
              },
              {
                "name": "263508",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1"
              },
              {
                "name": "36750",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/36750"
              },
              {
                "name": "20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Integer Underflow",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/506194/100/0/threaded"
              },
              {
                "name": "36200",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/36200"
              },
              {
                "name": "ADV-2009-2490",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2009/2490"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-09-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-11T19:57:01.000Z",
            "orgId": "44d08088-2bea-4760-83a6-1e9be26b15ab",
            "shortName": "flexera"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html"
            },
            {
              "name": "60799",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/60799"
            },
            {
              "name": "GLSA-201408-19",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://development.openoffice.org/releases/3.1.1.html"
            },
            {
              "name": "MDVSA-2010:105",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:105"
            },
            {
              "name": "MDVSA-2010:091",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:091"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://secunia.com/secunia_research/2009-26/"
            },
            {
              "name": "MDVSA-2010:035",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:035"
            },
            {
              "name": "1020715",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1"
            },
            {
              "name": "SUSE-SR:2009:015",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"
            },
            {
              "name": "DSA-1880",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2009/dsa-1880"
            },
            {
              "name": "oval:org.mitre.oval:def:10881",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10881"
            },
            {
              "name": "35036",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/35036"
            },
            {
              "name": "263508",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1"
            },
            {
              "name": "36750",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/36750"
            },
            {
              "name": "20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Integer Underflow",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/506194/100/0/threaded"
            },
            {
              "name": "36200",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/36200"
            },
            {
              "name": "ADV-2009-2490",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2009/2490"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "PSIRT-CNA@flexerasoftware.com",
              "ID": "CVE-2009-0200",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html"
                },
                {
                  "name": "60799",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/60799"
                },
                {
                  "name": "GLSA-201408-19",
                  "refsource": "GENTOO",
                  "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
                },
                {
                  "name": "http://development.openoffice.org/releases/3.1.1.html",
                  "refsource": "MISC",
                  "url": "http://development.openoffice.org/releases/3.1.1.html"
                },
                {
                  "name": "MDVSA-2010:105",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:105"
                },
                {
                  "name": "MDVSA-2010:091",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:091"
                },
                {
                  "name": "http://secunia.com/secunia_research/2009-26/",
                  "refsource": "MISC",
                  "url": "http://secunia.com/secunia_research/2009-26/"
                },
                {
                  "name": "MDVSA-2010:035",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:035"
                },
                {
                  "name": "1020715",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1"
                },
                {
                  "name": "SUSE-SR:2009:015",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"
                },
                {
                  "name": "DSA-1880",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2009/dsa-1880"
                },
                {
                  "name": "oval:org.mitre.oval:def:10881",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10881"
                },
                {
                  "name": "35036",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/35036"
                },
                {
                  "name": "263508",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1"
                },
                {
                  "name": "36750",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/36750"
                },
                {
                  "name": "20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Integer Underflow",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/506194/100/0/threaded"
                },
                {
                  "name": "36200",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/36200"
                },
                {
                  "name": "ADV-2009-2490",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2009/2490"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "44d08088-2bea-4760-83a6-1e9be26b15ab",
        "assignerShortName": "flexera",
        "cveId": "CVE-2009-0200",
        "datePublished": "2009-09-02T17:00:00.000Z",
        "dateReserved": "2009-01-20T00:00:00.000Z",
        "dateUpdated": "2024-08-07T04:24:18.284Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-0259 (GCVE-0-2009-0259)

    Vulnerability from nvd – Published: 2009-01-22 23:00 – Updated: 2024-08-07 04:24
    VLAI
    Summary
    The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Date Public
    2009-01-21 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T04:24:18.478Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "6560",
                "tags": [
                  "exploit",
                  "x_refsource_EXPLOIT-DB",
                  "x_transferred"
                ],
                "url": "https://www.exploit-db.com/exploits/6560"
              },
              {
                "name": "33383",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/33383"
              },
              {
                "name": "openoffice-wordprocessor-code-execution(48213)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48213"
              },
              {
                "name": "[oss-security] 20090121 CVE Request -- openoffice.org (CVE-2008-4841)",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2009/01/21/9"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://milw0rm.com/sploits/2008-crash.doc.rar"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-01-21T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-28T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "6560",
              "tags": [
                "exploit",
                "x_refsource_EXPLOIT-DB"
              ],
              "url": "https://www.exploit-db.com/exploits/6560"
            },
            {
              "name": "33383",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/33383"
            },
            {
              "name": "openoffice-wordprocessor-code-execution(48213)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48213"
            },
            {
              "name": "[oss-security] 20090121 CVE Request -- openoffice.org (CVE-2008-4841)",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2009/01/21/9"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://milw0rm.com/sploits/2008-crash.doc.rar"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2009-0259",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "6560",
                  "refsource": "EXPLOIT-DB",
                  "url": "https://www.exploit-db.com/exploits/6560"
                },
                {
                  "name": "33383",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/33383"
                },
                {
                  "name": "openoffice-wordprocessor-code-execution(48213)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48213"
                },
                {
                  "name": "[oss-security] 20090121 CVE Request -- openoffice.org (CVE-2008-4841)",
                  "refsource": "MLIST",
                  "url": "http://www.openwall.com/lists/oss-security/2009/01/21/9"
                },
                {
                  "name": "http://milw0rm.com/sploits/2008-crash.doc.rar",
                  "refsource": "MISC",
                  "url": "http://milw0rm.com/sploits/2008-crash.doc.rar"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2009-0259",
        "datePublished": "2009-01-22T23:00:00.000Z",
        "dateReserved": "2009-01-22T00:00:00.000Z",
        "dateUpdated": "2024-08-07T04:24:18.478Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2008-4937 (GCVE-0-2008-4937)

    Vulnerability from nvd – Published: 2008-11-05 14:51 – Updated: 2024-08-07 10:31
    VLAI
    Summary
    senddoc in OpenOffice.org (OOo) 2.4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/log.obr.##### temporary file.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.ubuntu.com/usn/usn-677-2 vendor-advisoryx_refsource_UBUNTU
    http://secunia.com/advisories/32856 third-party-advisoryx_refsource_SECUNIA
    http://bugs.debian.org/496361 x_refsource_CONFIRM
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://www.securityfocus.com/bid/30925 vdb-entryx_refsource_BID
    http://www.openwall.com/lists/oss-security/2008/10/30/2 mailing-listx_refsource_MLIST
    https://bugs.gentoo.org/show_bug.cgi?id=235770 x_refsource_CONFIRM
    http://uvw.ru/report.lenny.txt x_refsource_MISC
    http://www.ubuntu.com/usn/usn-677-1 vendor-advisoryx_refsource_UBUNTU
    http://security.gentoo.org/glsa/glsa-200812-13.xml vendor-advisoryx_refsource_GENTOO
    http://dev.gentoo.org/~rbu/security/debiantemp/op… x_refsource_CONFIRM
    https://bugs.gentoo.org/235824 x_refsource_CONFIRM
    http://secunia.com/advisories/33140 third-party-advisoryx_refsource_SECUNIA
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    Date Public
    2008-08-11 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T10:31:28.348Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "USN-677-2",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-677-2"
              },
              {
                "name": "32856",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32856"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://bugs.debian.org/496361"
              },
              {
                "name": "openoffice-senddoc-symlink(44829)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44829"
              },
              {
                "name": "30925",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/30925"
              },
              {
                "name": "[oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2008/10/30/2"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugs.gentoo.org/show_bug.cgi?id=235770"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://uvw.ru/report.lenny.txt"
              },
              {
                "name": "USN-677-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-677-1"
              },
              {
                "name": "GLSA-200812-13",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://dev.gentoo.org/~rbu/security/debiantemp/openoffice.org-common"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugs.gentoo.org/235824"
              },
              {
                "name": "33140",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/33140"
              },
              {
                "name": "MDVSA-2009:070",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:070"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2008-08-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "senddoc in OpenOffice.org (OOo) 2.4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/log.obr.##### temporary file."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-08-07T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "USN-677-2",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-677-2"
            },
            {
              "name": "32856",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32856"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://bugs.debian.org/496361"
            },
            {
              "name": "openoffice-senddoc-symlink(44829)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44829"
            },
            {
              "name": "30925",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/30925"
            },
            {
              "name": "[oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2008/10/30/2"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugs.gentoo.org/show_bug.cgi?id=235770"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://uvw.ru/report.lenny.txt"
            },
            {
              "name": "USN-677-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-677-1"
            },
            {
              "name": "GLSA-200812-13",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://dev.gentoo.org/~rbu/security/debiantemp/openoffice.org-common"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugs.gentoo.org/235824"
            },
            {
              "name": "33140",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/33140"
            },
            {
              "name": "MDVSA-2009:070",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:070"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2008-4937",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "senddoc in OpenOffice.org (OOo) 2.4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/log.obr.##### temporary file."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "USN-677-2",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-677-2"
                },
                {
                  "name": "32856",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32856"
                },
                {
                  "name": "http://bugs.debian.org/496361",
                  "refsource": "CONFIRM",
                  "url": "http://bugs.debian.org/496361"
                },
                {
                  "name": "openoffice-senddoc-symlink(44829)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44829"
                },
                {
                  "name": "30925",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/30925"
                },
                {
                  "name": "[oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire",
                  "refsource": "MLIST",
                  "url": "http://www.openwall.com/lists/oss-security/2008/10/30/2"
                },
                {
                  "name": "https://bugs.gentoo.org/show_bug.cgi?id=235770",
                  "refsource": "CONFIRM",
                  "url": "https://bugs.gentoo.org/show_bug.cgi?id=235770"
                },
                {
                  "name": "http://uvw.ru/report.lenny.txt",
                  "refsource": "MISC",
                  "url": "http://uvw.ru/report.lenny.txt"
                },
                {
                  "name": "USN-677-1",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-677-1"
                },
                {
                  "name": "GLSA-200812-13",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
                },
                {
                  "name": "http://dev.gentoo.org/~rbu/security/debiantemp/openoffice.org-common",
                  "refsource": "CONFIRM",
                  "url": "http://dev.gentoo.org/~rbu/security/debiantemp/openoffice.org-common"
                },
                {
                  "name": "https://bugs.gentoo.org/235824",
                  "refsource": "CONFIRM",
                  "url": "https://bugs.gentoo.org/235824"
                },
                {
                  "name": "33140",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/33140"
                },
                {
                  "name": "MDVSA-2009:070",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:070"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2008-4937",
        "datePublished": "2008-11-05T14:51:00.000Z",
        "dateReserved": "2008-11-05T00:00:00.000Z",
        "dateUpdated": "2024-08-07T10:31:28.348Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2008-2238 (GCVE-0-2008-2238)

    Vulnerability from nvd – Published: 2008-10-30 19:19 – Updated: 2024-08-07 08:49
    VLAI
    Summary
    Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.ubuntu.com/usn/usn-677-2 vendor-advisoryx_refsource_UBUNTU
    http://secunia.com/advisories/32856 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/bid/31962 vdb-entryx_refsource_BID
    http://labs.idefense.com/intelligence/vulnerabili… third-party-advisoryx_refsource_IDEFENSE
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://secunia.com/advisories/32461 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2008/3153 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/32419 third-party-advisoryx_refsource_SECUNIA
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    http://secunia.com/advisories/32872 third-party-advisoryx_refsource_SECUNIA
    http://neowiki.neooffice.org/index.php/NeoOffice_… x_refsource_CONFIRM
    http://www.ubuntu.com/usn/usn-677-1 vendor-advisoryx_refsource_UBUNTU
    http://security.gentoo.org/glsa/glsa-200812-13.xml vendor-advisoryx_refsource_GENTOO
    http://secunia.com/advisories/32676 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2008/3103 vdb-entryx_refsource_VUPEN
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://www.vupen.com/english/advisories/2008/2947 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/32489 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/32463 third-party-advisoryx_refsource_SECUNIA
    http://www.redhat.com/support/errata/RHSA-2008-09… vendor-advisoryx_refsource_REDHAT
    http://www.openoffice.org/security/cves/CVE-2008-… x_refsource_CONFIRM
    http://www.debian.org/security/2008/dsa-1661 vendor-advisoryx_refsource_DEBIAN
    http://www.securitytracker.com/id?1021121 vdb-entryx_refsource_SECTRACK
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://secunia.com/advisories/33140 third-party-advisoryx_refsource_SECUNIA
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    Date Public
    2008-10-29 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T08:49:58.915Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "USN-677-2",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-677-2"
              },
              {
                "name": "32856",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32856"
              },
              {
                "name": "31962",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/31962"
              },
              {
                "name": "20081031 OpenOffice EMF Record Parsing Multiple Integer Overflow Vulnerabilities",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_IDEFENSE",
                  "x_transferred"
                ],
                "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=750"
              },
              {
                "name": "oval:org.mitre.oval:def:10849",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10849"
              },
              {
                "name": "32461",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32461"
              },
              {
                "name": "ADV-2008-3153",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/3153"
              },
              {
                "name": "32419",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32419"
              },
              {
                "name": "FEDORA-2008-9333",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00923.html"
              },
              {
                "name": "32872",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32872"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes"
              },
              {
                "name": "USN-677-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-677-1"
              },
              {
                "name": "GLSA-200812-13",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
              },
              {
                "name": "32676",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32676"
              },
              {
                "name": "ADV-2008-3103",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/3103"
              },
              {
                "name": "243226",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-243226-1"
              },
              {
                "name": "ADV-2008-2947",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/2947"
              },
              {
                "name": "32489",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32489"
              },
              {
                "name": "32463",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32463"
              },
              {
                "name": "RHSA-2008:0939",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0939.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2008-2238.html"
              },
              {
                "name": "DSA-1661",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2008/dsa-1661"
              },
              {
                "name": "1021121",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1021121"
              },
              {
                "name": "SUSE-SR:2008:026",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html"
              },
              {
                "name": "33140",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/33140"
              },
              {
                "name": "openoffice-emf-file-bo(46166)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46166"
              },
              {
                "name": "FEDORA-2008-9313",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00905.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2008-10-29T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-28T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "USN-677-2",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-677-2"
            },
            {
              "name": "32856",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32856"
            },
            {
              "name": "31962",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/31962"
            },
            {
              "name": "20081031 OpenOffice EMF Record Parsing Multiple Integer Overflow Vulnerabilities",
              "tags": [
                "third-party-advisory",
                "x_refsource_IDEFENSE"
              ],
              "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=750"
            },
            {
              "name": "oval:org.mitre.oval:def:10849",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10849"
            },
            {
              "name": "32461",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32461"
            },
            {
              "name": "ADV-2008-3153",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/3153"
            },
            {
              "name": "32419",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32419"
            },
            {
              "name": "FEDORA-2008-9333",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00923.html"
            },
            {
              "name": "32872",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32872"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes"
            },
            {
              "name": "USN-677-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-677-1"
            },
            {
              "name": "GLSA-200812-13",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
            },
            {
              "name": "32676",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32676"
            },
            {
              "name": "ADV-2008-3103",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/3103"
            },
            {
              "name": "243226",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-243226-1"
            },
            {
              "name": "ADV-2008-2947",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/2947"
            },
            {
              "name": "32489",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32489"
            },
            {
              "name": "32463",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32463"
            },
            {
              "name": "RHSA-2008:0939",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0939.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2008-2238.html"
            },
            {
              "name": "DSA-1661",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2008/dsa-1661"
            },
            {
              "name": "1021121",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1021121"
            },
            {
              "name": "SUSE-SR:2008:026",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html"
            },
            {
              "name": "33140",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/33140"
            },
            {
              "name": "openoffice-emf-file-bo(46166)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46166"
            },
            {
              "name": "FEDORA-2008-9313",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00905.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2008-2238",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "USN-677-2",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-677-2"
                },
                {
                  "name": "32856",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32856"
                },
                {
                  "name": "31962",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/31962"
                },
                {
                  "name": "20081031 OpenOffice EMF Record Parsing Multiple Integer Overflow Vulnerabilities",
                  "refsource": "IDEFENSE",
                  "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=750"
                },
                {
                  "name": "oval:org.mitre.oval:def:10849",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10849"
                },
                {
                  "name": "32461",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32461"
                },
                {
                  "name": "ADV-2008-3153",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/3153"
                },
                {
                  "name": "32419",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32419"
                },
                {
                  "name": "FEDORA-2008-9333",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00923.html"
                },
                {
                  "name": "32872",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32872"
                },
                {
                  "name": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes",
                  "refsource": "CONFIRM",
                  "url": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes"
                },
                {
                  "name": "USN-677-1",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-677-1"
                },
                {
                  "name": "GLSA-200812-13",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
                },
                {
                  "name": "32676",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32676"
                },
                {
                  "name": "ADV-2008-3103",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/3103"
                },
                {
                  "name": "243226",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-243226-1"
                },
                {
                  "name": "ADV-2008-2947",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/2947"
                },
                {
                  "name": "32489",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32489"
                },
                {
                  "name": "32463",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32463"
                },
                {
                  "name": "RHSA-2008:0939",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2008-0939.html"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2008-2238.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2008-2238.html"
                },
                {
                  "name": "DSA-1661",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2008/dsa-1661"
                },
                {
                  "name": "1021121",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1021121"
                },
                {
                  "name": "SUSE-SR:2008:026",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html"
                },
                {
                  "name": "33140",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/33140"
                },
                {
                  "name": "openoffice-emf-file-bo(46166)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46166"
                },
                {
                  "name": "FEDORA-2008-9313",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00905.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2008-2238",
        "datePublished": "2008-10-30T19:19:00.000Z",
        "dateReserved": "2008-05-16T00:00:00.000Z",
        "dateUpdated": "2024-08-07T08:49:58.915Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2008-2237 (GCVE-0-2008-2237)

    Vulnerability from nvd – Published: 2008-10-30 19:19 – Updated: 2024-08-07 08:49
    VLAI
    Summary
    Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associated with a StarOffice/StarSuite document.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.ubuntu.com/usn/usn-677-2 vendor-advisoryx_refsource_UBUNTU
    http://secunia.com/advisories/32856 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/bid/31962 vdb-entryx_refsource_BID
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://secunia.com/advisories/32461 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/32419 third-party-advisoryx_refsource_SECUNIA
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    http://secunia.com/advisories/32872 third-party-advisoryx_refsource_SECUNIA
    http://neowiki.neooffice.org/index.php/NeoOffice_… x_refsource_CONFIRM
    http://www.ubuntu.com/usn/usn-677-1 vendor-advisoryx_refsource_UBUNTU
    http://security.gentoo.org/glsa/glsa-200812-13.xml vendor-advisoryx_refsource_GENTOO
    http://secunia.com/advisories/32676 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2008/3103 vdb-entryx_refsource_VUPEN
    http://www.vupen.com/english/advisories/2008/2947 vdb-entryx_refsource_VUPEN
    http://www.openoffice.org/security/cves/CVE-2008-… x_refsource_CONFIRM
    http://secunia.com/advisories/32489 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/32463 third-party-advisoryx_refsource_SECUNIA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://www.securitytracker.com/id?1021120 vdb-entryx_refsource_SECTRACK
    http://www.redhat.com/support/errata/RHSA-2008-09… vendor-advisoryx_refsource_REDHAT
    http://www.debian.org/security/2008/dsa-1661 vendor-advisoryx_refsource_DEBIAN
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://secunia.com/advisories/33140 third-party-advisoryx_refsource_SECUNIA
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    Date Public
    2008-10-29 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T08:49:58.925Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "USN-677-2",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-677-2"
              },
              {
                "name": "32856",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32856"
              },
              {
                "name": "31962",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/31962"
              },
              {
                "name": "openoffice-wmf-bo(46165)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46165"
              },
              {
                "name": "32461",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32461"
              },
              {
                "name": "32419",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32419"
              },
              {
                "name": "oval:org.mitre.oval:def:10784",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10784"
              },
              {
                "name": "FEDORA-2008-9333",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00923.html"
              },
              {
                "name": "32872",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32872"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes"
              },
              {
                "name": "USN-677-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-677-1"
              },
              {
                "name": "GLSA-200812-13",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
              },
              {
                "name": "32676",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32676"
              },
              {
                "name": "ADV-2008-3103",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/3103"
              },
              {
                "name": "ADV-2008-2947",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/2947"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2008-2237.html"
              },
              {
                "name": "32489",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32489"
              },
              {
                "name": "32463",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32463"
              },
              {
                "name": "242627",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-242627-1"
              },
              {
                "name": "1021120",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1021120"
              },
              {
                "name": "RHSA-2008:0939",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0939.html"
              },
              {
                "name": "DSA-1661",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2008/dsa-1661"
              },
              {
                "name": "SUSE-SR:2008:026",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html"
              },
              {
                "name": "33140",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/33140"
              },
              {
                "name": "FEDORA-2008-9313",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00905.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2008-10-29T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associated with a StarOffice/StarSuite document."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-28T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "USN-677-2",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-677-2"
            },
            {
              "name": "32856",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32856"
            },
            {
              "name": "31962",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/31962"
            },
            {
              "name": "openoffice-wmf-bo(46165)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46165"
            },
            {
              "name": "32461",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32461"
            },
            {
              "name": "32419",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32419"
            },
            {
              "name": "oval:org.mitre.oval:def:10784",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10784"
            },
            {
              "name": "FEDORA-2008-9333",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00923.html"
            },
            {
              "name": "32872",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32872"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes"
            },
            {
              "name": "USN-677-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-677-1"
            },
            {
              "name": "GLSA-200812-13",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
            },
            {
              "name": "32676",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32676"
            },
            {
              "name": "ADV-2008-3103",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/3103"
            },
            {
              "name": "ADV-2008-2947",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/2947"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2008-2237.html"
            },
            {
              "name": "32489",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32489"
            },
            {
              "name": "32463",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32463"
            },
            {
              "name": "242627",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-242627-1"
            },
            {
              "name": "1021120",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1021120"
            },
            {
              "name": "RHSA-2008:0939",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0939.html"
            },
            {
              "name": "DSA-1661",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2008/dsa-1661"
            },
            {
              "name": "SUSE-SR:2008:026",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html"
            },
            {
              "name": "33140",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/33140"
            },
            {
              "name": "FEDORA-2008-9313",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00905.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2008-2237",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associated with a StarOffice/StarSuite document."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "USN-677-2",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-677-2"
                },
                {
                  "name": "32856",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32856"
                },
                {
                  "name": "31962",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/31962"
                },
                {
                  "name": "openoffice-wmf-bo(46165)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46165"
                },
                {
                  "name": "32461",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32461"
                },
                {
                  "name": "32419",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32419"
                },
                {
                  "name": "oval:org.mitre.oval:def:10784",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10784"
                },
                {
                  "name": "FEDORA-2008-9333",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00923.html"
                },
                {
                  "name": "32872",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32872"
                },
                {
                  "name": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes",
                  "refsource": "CONFIRM",
                  "url": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes"
                },
                {
                  "name": "USN-677-1",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-677-1"
                },
                {
                  "name": "GLSA-200812-13",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
                },
                {
                  "name": "32676",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32676"
                },
                {
                  "name": "ADV-2008-3103",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/3103"
                },
                {
                  "name": "ADV-2008-2947",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/2947"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2008-2237.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2008-2237.html"
                },
                {
                  "name": "32489",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32489"
                },
                {
                  "name": "32463",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32463"
                },
                {
                  "name": "242627",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-242627-1"
                },
                {
                  "name": "1021120",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1021120"
                },
                {
                  "name": "RHSA-2008:0939",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2008-0939.html"
                },
                {
                  "name": "DSA-1661",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2008/dsa-1661"
                },
                {
                  "name": "SUSE-SR:2008:026",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html"
                },
                {
                  "name": "33140",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/33140"
                },
                {
                  "name": "FEDORA-2008-9313",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00905.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2008-2237",
        "datePublished": "2008-10-30T19:19:00.000Z",
        "dateReserved": "2008-05-16T00:00:00.000Z",
        "dateUpdated": "2024-08-07T08:49:58.925Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2008-3437 (GCVE-0-2008-3437)

    Vulnerability from nvd – Published: 2008-08-01 14:00 – Updated: 2024-09-16 19:30
    VLAI
    Summary
    OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T09:37:26.904Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://www.infobyte.com.ar/down/Francisco%20Amato%20-%20evilgrade%20-%20ENG.pdf"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://www.infobyte.com.ar/down/isr-evilgrade-1.0.0.tar.gz"
              },
              {
                "name": "1020583",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1020583"
              },
              {
                "name": "20080728 Tool release: [evilgrade] - Using DNS cache poisoning to exploit poor update implementations",
                "tags": [
                  "mailing-list",
                  "x_refsource_FULLDISC",
                  "x_transferred"
                ],
                "url": "http://archives.neohapsis.com/archives/bugtraq/2008-07/0250.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2008-08-01T14:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://www.infobyte.com.ar/down/Francisco%20Amato%20-%20evilgrade%20-%20ENG.pdf"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://www.infobyte.com.ar/down/isr-evilgrade-1.0.0.tar.gz"
            },
            {
              "name": "1020583",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://securitytracker.com/id?1020583"
            },
            {
              "name": "20080728 Tool release: [evilgrade] - Using DNS cache poisoning to exploit poor update implementations",
              "tags": [
                "mailing-list",
                "x_refsource_FULLDISC"
              ],
              "url": "http://archives.neohapsis.com/archives/bugtraq/2008-07/0250.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2008-3437",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.infobyte.com.ar/down/Francisco%20Amato%20-%20evilgrade%20-%20ENG.pdf",
                  "refsource": "MISC",
                  "url": "http://www.infobyte.com.ar/down/Francisco%20Amato%20-%20evilgrade%20-%20ENG.pdf"
                },
                {
                  "name": "http://www.infobyte.com.ar/down/isr-evilgrade-1.0.0.tar.gz",
                  "refsource": "MISC",
                  "url": "http://www.infobyte.com.ar/down/isr-evilgrade-1.0.0.tar.gz"
                },
                {
                  "name": "1020583",
                  "refsource": "SECTRACK",
                  "url": "http://securitytracker.com/id?1020583"
                },
                {
                  "name": "20080728 Tool release: [evilgrade] - Using DNS cache poisoning to exploit poor update implementations",
                  "refsource": "FULLDISC",
                  "url": "http://archives.neohapsis.com/archives/bugtraq/2008-07/0250.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2008-3437",
        "datePublished": "2008-08-01T14:00:00.000Z",
        "dateReserved": "2008-08-01T00:00:00.000Z",
        "dateUpdated": "2024-09-16T19:30:38.697Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2008-2366 (GCVE-0-2008-2366)

    Vulnerability from nvd – Published: 2008-06-16 18:26 – Updated: 2024-08-07 08:58
    VLAI
    Summary
    Untrusted search path vulnerability in a certain Red Hat build script for OpenOffice.org (OOo) 1.1.x on Red Hat Enterprise Linux (RHEL) 3 and 4 allows local users to gain privileges via a malicious library in the current working directory, related to incorrect quoting of the ORIGIN symbol for use in the RPATH library path.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    https://bugzilla.redhat.com/show_bug.cgi?id=450532 x_refsource_CONFIRM
    http://secunia.com/advisories/30633 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/bid/29695 vdb-entryx_refsource_BID
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://www.redhat.com/support/errata/RHSA-2008-05… vendor-advisoryx_refsource_REDHAT
    http://securitytracker.com/id?1020278 vdb-entryx_refsource_SECTRACK
    Date Public
    2008-06-12 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T08:58:02.116Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=450532"
              },
              {
                "name": "30633",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30633"
              },
              {
                "name": "29695",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/29695"
              },
              {
                "name": "oval:org.mitre.oval:def:11361",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11361"
              },
              {
                "name": "redhat-ooo-buildscript-code-execution(43322)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43322"
              },
              {
                "name": "RHSA-2008:0538",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0538.html"
              },
              {
                "name": "1020278",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1020278"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2008-06-12T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Untrusted search path vulnerability in a certain Red Hat build script for OpenOffice.org (OOo) 1.1.x on Red Hat Enterprise Linux (RHEL) 3 and 4 allows local users to gain privileges via a malicious library in the current working directory, related to incorrect quoting of the ORIGIN symbol for use in the RPATH library path."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-28T12:57:01.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=450532"
            },
            {
              "name": "30633",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30633"
            },
            {
              "name": "29695",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/29695"
            },
            {
              "name": "oval:org.mitre.oval:def:11361",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11361"
            },
            {
              "name": "redhat-ooo-buildscript-code-execution(43322)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43322"
            },
            {
              "name": "RHSA-2008:0538",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0538.html"
            },
            {
              "name": "1020278",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://securitytracker.com/id?1020278"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2008-2366",
        "datePublished": "2008-06-16T18:26:00.000Z",
        "dateReserved": "2008-05-21T00:00:00.000Z",
        "dateUpdated": "2024-08-07T08:58:02.116Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2008-2152 (GCVE-0-2008-2152)

    Vulnerability from nvd – Published: 2008-06-10 18:00 – Updated: 2024-08-07 08:49
    VLAI
    Summary
    Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://secunia.com/advisories/30635 third-party-advisoryx_refsource_SECUNIA
    http://www.redhat.com/support/errata/RHSA-2008-05… vendor-advisoryx_refsource_REDHAT
    http://secunia.com/advisories/30633 third-party-advisoryx_refsource_SECUNIA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    http://www.securitytracker.com/id?1020219 vdb-entryx_refsource_SECTRACK
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    http://security.gentoo.org/glsa/glsa-200807-05.xml vendor-advisoryx_refsource_GENTOO
    http://www.vupen.com/english/advisories/2008/1804… vdb-entryx_refsource_VUPEN
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.openoffice.org/security/cves/CVE-2008-… x_refsource_CONFIRM
    http://www.redhat.com/support/errata/RHSA-2008-05… vendor-advisoryx_refsource_REDHAT
    http://secunia.com/advisories/30634 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/30599 third-party-advisoryx_refsource_SECUNIA
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    http://labs.idefense.com/intelligence/vulnerabili… third-party-advisoryx_refsource_IDEFENSE
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://www.vupen.com/english/advisories/2008/1773 vdb-entryx_refsource_VUPEN
    http://www.securityfocus.com/bid/29622 vdb-entryx_refsource_BID
    http://secunia.com/advisories/31029 third-party-advisoryx_refsource_SECUNIA
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    Date Public
    2008-06-10 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T08:49:58.488Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "30635",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30635"
              },
              {
                "name": "RHSA-2008:0537",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0537.html"
              },
              {
                "name": "30633",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30633"
              },
              {
                "name": "237944",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-237944-1"
              },
              {
                "name": "FEDORA-2008-5143",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00385.html"
              },
              {
                "name": "1020219",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1020219"
              },
              {
                "name": "FEDORA-2008-5247",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00499.html"
              },
              {
                "name": "GLSA-200807-05",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-200807-05.xml"
              },
              {
                "name": "ADV-2008-1804",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/1804/references"
              },
              {
                "name": "oval:org.mitre.oval:def:9787",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9787"
              },
              {
                "name": "MDVSA-2008:138",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:138"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2008-2152.html"
              },
              {
                "name": "RHSA-2008:0538",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0538.html"
              },
              {
                "name": "30634",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30634"
              },
              {
                "name": "30599",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30599"
              },
              {
                "name": "FEDORA-2008-5239",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00473.html"
              },
              {
                "name": "20080610 Multiple Vendor OpenOffice rtl_allocateMemory() Integer Overflow Vulnerability",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_IDEFENSE",
                  "x_transferred"
                ],
                "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=714"
              },
              {
                "name": "openoffice-rtlallocatememory-bo(42957)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42957"
              },
              {
                "name": "ADV-2008-1773",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/1773"
              },
              {
                "name": "29622",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/29622"
              },
              {
                "name": "31029",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/31029"
              },
              {
                "name": "MDVSA-2008:137",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:137"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2008-06-10T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-28T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "30635",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30635"
            },
            {
              "name": "RHSA-2008:0537",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0537.html"
            },
            {
              "name": "30633",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30633"
            },
            {
              "name": "237944",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-237944-1"
            },
            {
              "name": "FEDORA-2008-5143",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00385.html"
            },
            {
              "name": "1020219",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1020219"
            },
            {
              "name": "FEDORA-2008-5247",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00499.html"
            },
            {
              "name": "GLSA-200807-05",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-200807-05.xml"
            },
            {
              "name": "ADV-2008-1804",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/1804/references"
            },
            {
              "name": "oval:org.mitre.oval:def:9787",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9787"
            },
            {
              "name": "MDVSA-2008:138",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:138"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2008-2152.html"
            },
            {
              "name": "RHSA-2008:0538",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0538.html"
            },
            {
              "name": "30634",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30634"
            },
            {
              "name": "30599",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30599"
            },
            {
              "name": "FEDORA-2008-5239",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00473.html"
            },
            {
              "name": "20080610 Multiple Vendor OpenOffice rtl_allocateMemory() Integer Overflow Vulnerability",
              "tags": [
                "third-party-advisory",
                "x_refsource_IDEFENSE"
              ],
              "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=714"
            },
            {
              "name": "openoffice-rtlallocatememory-bo(42957)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42957"
            },
            {
              "name": "ADV-2008-1773",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/1773"
            },
            {
              "name": "29622",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/29622"
            },
            {
              "name": "31029",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/31029"
            },
            {
              "name": "MDVSA-2008:137",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:137"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2008-2152",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "30635",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30635"
                },
                {
                  "name": "RHSA-2008:0537",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2008-0537.html"
                },
                {
                  "name": "30633",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30633"
                },
                {
                  "name": "237944",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-237944-1"
                },
                {
                  "name": "FEDORA-2008-5143",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00385.html"
                },
                {
                  "name": "1020219",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1020219"
                },
                {
                  "name": "FEDORA-2008-5247",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00499.html"
                },
                {
                  "name": "GLSA-200807-05",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-200807-05.xml"
                },
                {
                  "name": "ADV-2008-1804",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/1804/references"
                },
                {
                  "name": "oval:org.mitre.oval:def:9787",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9787"
                },
                {
                  "name": "MDVSA-2008:138",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:138"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2008-2152.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2008-2152.html"
                },
                {
                  "name": "RHSA-2008:0538",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2008-0538.html"
                },
                {
                  "name": "30634",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30634"
                },
                {
                  "name": "30599",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30599"
                },
                {
                  "name": "FEDORA-2008-5239",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00473.html"
                },
                {
                  "name": "20080610 Multiple Vendor OpenOffice rtl_allocateMemory() Integer Overflow Vulnerability",
                  "refsource": "IDEFENSE",
                  "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=714"
                },
                {
                  "name": "openoffice-rtlallocatememory-bo(42957)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42957"
                },
                {
                  "name": "ADV-2008-1773",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/1773"
                },
                {
                  "name": "29622",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/29622"
                },
                {
                  "name": "31029",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/31029"
                },
                {
                  "name": "MDVSA-2008:137",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:137"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2008-2152",
        "datePublished": "2008-06-10T18:00:00.000Z",
        "dateReserved": "2008-05-12T00:00:00.000Z",
        "dateUpdated": "2024-08-07T08:49:58.488Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2008-0320 (GCVE-0-2008-0320)

    Vulnerability from nvd – Published: 2008-04-17 17:00 – Updated: 2024-08-07 07:39
    VLAI
    Summary
    Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://secunia.com/advisories/29913 third-party-advisoryx_refsource_SECUNIA
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.redhat.com/support/errata/RHSA-2008-01… vendor-advisoryx_refsource_REDHAT
    http://secunia.com/advisories/29852 third-party-advisoryx_refsource_SECUNIA
    http://www.novell.com/linux/security/advisories/2… vendor-advisoryx_refsource_SUSE
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://labs.idefense.com/intelligence/vulnerabili… third-party-advisoryx_refsource_IDEFENSE
    http://secunia.com/advisories/29864 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/29844 third-party-advisoryx_refsource_SECUNIA
    http://security.gentoo.org/glsa/glsa-200805-16.xml vendor-advisoryx_refsource_GENTOO
    http://secunia.com/advisories/30100 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/29987 third-party-advisoryx_refsource_SECUNIA
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.securitytracker.com/id?1019890 vdb-entryx_refsource_SECTRACK
    http://www.openoffice.org/security/cves/CVE-2007-… x_refsource_CONFIRM
    http://www.debian.org/security/2008/dsa-1547 vendor-advisoryx_refsource_DEBIAN
    http://www.vupen.com/english/advisories/2008/1253… vdb-entryx_refsource_VUPEN
    http://www.openoffice.org/security/cves/CVE-2008-… x_refsource_CONFIRM
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.redhat.com/support/errata/RHSA-2008-01… vendor-advisoryx_refsource_REDHAT
    http://www.vupen.com/english/advisories/2008/1375… vdb-entryx_refsource_VUPEN
    http://www.openoffice.org/security/bulletin.html x_refsource_CONFIRM
    http://secunia.com/advisories/30179 third-party-advisoryx_refsource_SECUNIA
    http://www.openoffice.org/security/cves/CVE-2007-… x_refsource_CONFIRM
    http://www.securityfocus.com/bid/28819 vdb-entryx_refsource_BID
    http://secunia.com/advisories/29871 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/29910 third-party-advisoryx_refsource_SECUNIA
    http://www.ubuntu.com/usn/usn-609-1 vendor-advisoryx_refsource_UBUNTU
    Date Public
    2008-04-17 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T07:39:35.181Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "29913",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29913"
              },
              {
                "name": "MDVSA-2008:090",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:090"
              },
              {
                "name": "RHSA-2008:0175",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0175.html"
              },
              {
                "name": "29852",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29852"
              },
              {
                "name": "SUSE-SA:2008:023",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://www.novell.com/linux/security/advisories/2008_23_openoffice.html"
              },
              {
                "name": "openoffice-ole-bo(41860)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41860"
              },
              {
                "name": "20080417 Multiple Vendor OpenOffice OLE DocumentSummaryInformation Heap Overflow Vulnerability",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_IDEFENSE",
                  "x_transferred"
                ],
                "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=694"
              },
              {
                "name": "29864",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29864"
              },
              {
                "name": "29844",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29844"
              },
              {
                "name": "GLSA-200805-16",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-200805-16.xml"
              },
              {
                "name": "30100",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30100"
              },
              {
                "name": "29987",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29987"
              },
              {
                "name": "MDVSA-2008:095",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:095"
              },
              {
                "name": "1019890",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1019890"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2007-4770.html"
              },
              {
                "name": "DSA-1547",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2008/dsa-1547"
              },
              {
                "name": "ADV-2008-1253",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/1253/references"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2008-0320.html"
              },
              {
                "name": "FEDORA-2008-3251",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html"
              },
              {
                "name": "231642",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-231642-1"
              },
              {
                "name": "oval:org.mitre.oval:def:10318",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10318"
              },
              {
                "name": "RHSA-2008:0176",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0176.html"
              },
              {
                "name": "ADV-2008-1375",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/1375/references"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/bulletin.html"
              },
              {
                "name": "30179",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30179"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2007-5745.html"
              },
              {
                "name": "28819",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/28819"
              },
              {
                "name": "29871",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29871"
              },
              {
                "name": "29910",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29910"
              },
              {
                "name": "USN-609-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-609-1"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2008-04-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-28T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "29913",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29913"
            },
            {
              "name": "MDVSA-2008:090",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:090"
            },
            {
              "name": "RHSA-2008:0175",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0175.html"
            },
            {
              "name": "29852",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29852"
            },
            {
              "name": "SUSE-SA:2008:023",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://www.novell.com/linux/security/advisories/2008_23_openoffice.html"
            },
            {
              "name": "openoffice-ole-bo(41860)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41860"
            },
            {
              "name": "20080417 Multiple Vendor OpenOffice OLE DocumentSummaryInformation Heap Overflow Vulnerability",
              "tags": [
                "third-party-advisory",
                "x_refsource_IDEFENSE"
              ],
              "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=694"
            },
            {
              "name": "29864",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29864"
            },
            {
              "name": "29844",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29844"
            },
            {
              "name": "GLSA-200805-16",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-200805-16.xml"
            },
            {
              "name": "30100",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30100"
            },
            {
              "name": "29987",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29987"
            },
            {
              "name": "MDVSA-2008:095",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:095"
            },
            {
              "name": "1019890",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1019890"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2007-4770.html"
            },
            {
              "name": "DSA-1547",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2008/dsa-1547"
            },
            {
              "name": "ADV-2008-1253",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/1253/references"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2008-0320.html"
            },
            {
              "name": "FEDORA-2008-3251",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html"
            },
            {
              "name": "231642",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-231642-1"
            },
            {
              "name": "oval:org.mitre.oval:def:10318",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10318"
            },
            {
              "name": "RHSA-2008:0176",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0176.html"
            },
            {
              "name": "ADV-2008-1375",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/1375/references"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/bulletin.html"
            },
            {
              "name": "30179",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30179"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2007-5745.html"
            },
            {
              "name": "28819",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/28819"
            },
            {
              "name": "29871",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29871"
            },
            {
              "name": "29910",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29910"
            },
            {
              "name": "USN-609-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-609-1"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2008-0320",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "29913",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29913"
                },
                {
                  "name": "MDVSA-2008:090",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:090"
                },
                {
                  "name": "RHSA-2008:0175",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2008-0175.html"
                },
                {
                  "name": "29852",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29852"
                },
                {
                  "name": "SUSE-SA:2008:023",
                  "refsource": "SUSE",
                  "url": "http://www.novell.com/linux/security/advisories/2008_23_openoffice.html"
                },
                {
                  "name": "openoffice-ole-bo(41860)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41860"
                },
                {
                  "name": "20080417 Multiple Vendor OpenOffice OLE DocumentSummaryInformation Heap Overflow Vulnerability",
                  "refsource": "IDEFENSE",
                  "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=694"
                },
                {
                  "name": "29864",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29864"
                },
                {
                  "name": "29844",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29844"
                },
                {
                  "name": "GLSA-200805-16",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-200805-16.xml"
                },
                {
                  "name": "30100",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30100"
                },
                {
                  "name": "29987",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29987"
                },
                {
                  "name": "MDVSA-2008:095",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:095"
                },
                {
                  "name": "1019890",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1019890"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2007-4770.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2007-4770.html"
                },
                {
                  "name": "DSA-1547",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2008/dsa-1547"
                },
                {
                  "name": "ADV-2008-1253",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/1253/references"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2008-0320.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2008-0320.html"
                },
                {
                  "name": "FEDORA-2008-3251",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html"
                },
                {
                  "name": "231642",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-231642-1"
                },
                {
                  "name": "oval:org.mitre.oval:def:10318",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10318"
                },
                {
                  "name": "RHSA-2008:0176",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2008-0176.html"
                },
                {
                  "name": "ADV-2008-1375",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/1375/references"
                },
                {
                  "name": "http://www.openoffice.org/security/bulletin.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/bulletin.html"
                },
                {
                  "name": "30179",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30179"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2007-5745.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2007-5745.html"
                },
                {
                  "name": "28819",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/28819"
                },
                {
                  "name": "29871",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29871"
                },
                {
                  "name": "29910",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29910"
                },
                {
                  "name": "USN-609-1",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-609-1"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2008-0320",
        "datePublished": "2008-04-17T17:00:00.000Z",
        "dateReserved": "2008-01-16T00:00:00.000Z",
        "dateUpdated": "2024-08-07T07:39:35.181Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2007-5745 (GCVE-0-2007-5745)

    Vulnerability from nvd – Published: 2008-04-17 17:00 – Updated: 2024-08-07 15:39
    VLAI
    Summary
    Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted (1) Attribute and (2) Font Description records.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://secunia.com/advisories/29913 third-party-advisoryx_refsource_SECUNIA
    http://www.redhat.com/support/errata/RHSA-2008-01… vendor-advisoryx_refsource_REDHAT
    http://secunia.com/advisories/29852 third-party-advisoryx_refsource_SECUNIA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://www.novell.com/linux/security/advisories/2… vendor-advisoryx_refsource_SUSE
    https://bugzilla.redhat.com/show_bug.cgi?id=435678 x_refsource_MISC
    http://labs.idefense.com/intelligence/vulnerabili… third-party-advisoryx_refsource_IDEFENSE
    http://secunia.com/advisories/29864 third-party-advisoryx_refsource_SECUNIA
    http://security.gentoo.org/glsa/glsa-200805-16.xml vendor-advisoryx_refsource_GENTOO
    http://secunia.com/advisories/30100 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/29987 third-party-advisoryx_refsource_SECUNIA
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.securitytracker.com/id?1019891 vdb-entryx_refsource_SECTRACK
    http://www.openoffice.org/security/cves/CVE-2007-… x_refsource_CONFIRM
    http://www.debian.org/security/2008/dsa-1547 vendor-advisoryx_refsource_DEBIAN
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.vupen.com/english/advisories/2008/1253… vdb-entryx_refsource_VUPEN
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    http://www.vupen.com/english/advisories/2008/1375… vdb-entryx_refsource_VUPEN
    http://www.openoffice.org/security/bulletin.html x_refsource_CONFIRM
    http://secunia.com/advisories/30179 third-party-advisoryx_refsource_SECUNIA
    http://www.openoffice.org/security/cves/CVE-2007-… x_refsource_CONFIRM
    http://www.securityfocus.com/bid/28819 vdb-entryx_refsource_BID
    http://secunia.com/advisories/29871 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/29910 third-party-advisoryx_refsource_SECUNIA
    http://www.ubuntu.com/usn/usn-609-1 vendor-advisoryx_refsource_UBUNTU
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    Date Public
    2008-04-17 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T15:39:13.807Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "29913",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29913"
              },
              {
                "name": "RHSA-2008:0175",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0175.html"
              },
              {
                "name": "29852",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29852"
              },
              {
                "name": "231601",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-231601-1"
              },
              {
                "name": "SUSE-SA:2008:023",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://www.novell.com/linux/security/advisories/2008_23_openoffice.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=435678"
              },
              {
                "name": "20080417 Multiple Vendor OpenOffice QPRO Multiple Heap Overflow Vulnerabilities",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_IDEFENSE",
                  "x_transferred"
                ],
                "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=691"
              },
              {
                "name": "29864",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29864"
              },
              {
                "name": "GLSA-200805-16",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-200805-16.xml"
              },
              {
                "name": "30100",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30100"
              },
              {
                "name": "29987",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29987"
              },
              {
                "name": "MDVSA-2008:095",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:095"
              },
              {
                "name": "1019891",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1019891"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2007-4770.html"
              },
              {
                "name": "DSA-1547",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2008/dsa-1547"
              },
              {
                "name": "oval:org.mitre.oval:def:11006",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11006"
              },
              {
                "name": "ADV-2008-1253",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/1253/references"
              },
              {
                "name": "FEDORA-2008-3251",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html"
              },
              {
                "name": "ADV-2008-1375",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/1375/references"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/bulletin.html"
              },
              {
                "name": "30179",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30179"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2007-5745.html"
              },
              {
                "name": "28819",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/28819"
              },
              {
                "name": "29871",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29871"
              },
              {
                "name": "29910",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29910"
              },
              {
                "name": "USN-609-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-609-1"
              },
              {
                "name": "openoffice-quattropro-bo(41863)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41863"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2008-04-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted (1) Attribute and (2) Font Description records."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-28T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "29913",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29913"
            },
            {
              "name": "RHSA-2008:0175",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0175.html"
            },
            {
              "name": "29852",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29852"
            },
            {
              "name": "231601",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-231601-1"
            },
            {
              "name": "SUSE-SA:2008:023",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://www.novell.com/linux/security/advisories/2008_23_openoffice.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=435678"
            },
            {
              "name": "20080417 Multiple Vendor OpenOffice QPRO Multiple Heap Overflow Vulnerabilities",
              "tags": [
                "third-party-advisory",
                "x_refsource_IDEFENSE"
              ],
              "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=691"
            },
            {
              "name": "29864",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29864"
            },
            {
              "name": "GLSA-200805-16",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-200805-16.xml"
            },
            {
              "name": "30100",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30100"
            },
            {
              "name": "29987",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29987"
            },
            {
              "name": "MDVSA-2008:095",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:095"
            },
            {
              "name": "1019891",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1019891"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2007-4770.html"
            },
            {
              "name": "DSA-1547",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2008/dsa-1547"
            },
            {
              "name": "oval:org.mitre.oval:def:11006",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11006"
            },
            {
              "name": "ADV-2008-1253",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/1253/references"
            },
            {
              "name": "FEDORA-2008-3251",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html"
            },
            {
              "name": "ADV-2008-1375",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/1375/references"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/bulletin.html"
            },
            {
              "name": "30179",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30179"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2007-5745.html"
            },
            {
              "name": "28819",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/28819"
            },
            {
              "name": "29871",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29871"
            },
            {
              "name": "29910",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29910"
            },
            {
              "name": "USN-609-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-609-1"
            },
            {
              "name": "openoffice-quattropro-bo(41863)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41863"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2007-5745",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted (1) Attribute and (2) Font Description records."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "29913",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29913"
                },
                {
                  "name": "RHSA-2008:0175",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2008-0175.html"
                },
                {
                  "name": "29852",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29852"
                },
                {
                  "name": "231601",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-231601-1"
                },
                {
                  "name": "SUSE-SA:2008:023",
                  "refsource": "SUSE",
                  "url": "http://www.novell.com/linux/security/advisories/2008_23_openoffice.html"
                },
                {
                  "name": "https://bugzilla.redhat.com/show_bug.cgi?id=435678",
                  "refsource": "MISC",
                  "url": "https://bugzilla.redhat.com/show_bug.cgi?id=435678"
                },
                {
                  "name": "20080417 Multiple Vendor OpenOffice QPRO Multiple Heap Overflow Vulnerabilities",
                  "refsource": "IDEFENSE",
                  "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=691"
                },
                {
                  "name": "29864",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29864"
                },
                {
                  "name": "GLSA-200805-16",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-200805-16.xml"
                },
                {
                  "name": "30100",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30100"
                },
                {
                  "name": "29987",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29987"
                },
                {
                  "name": "MDVSA-2008:095",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:095"
                },
                {
                  "name": "1019891",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1019891"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2007-4770.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2007-4770.html"
                },
                {
                  "name": "DSA-1547",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2008/dsa-1547"
                },
                {
                  "name": "oval:org.mitre.oval:def:11006",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11006"
                },
                {
                  "name": "ADV-2008-1253",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/1253/references"
                },
                {
                  "name": "FEDORA-2008-3251",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html"
                },
                {
                  "name": "ADV-2008-1375",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/1375/references"
                },
                {
                  "name": "http://www.openoffice.org/security/bulletin.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/bulletin.html"
                },
                {
                  "name": "30179",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30179"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2007-5745.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2007-5745.html"
                },
                {
                  "name": "28819",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/28819"
                },
                {
                  "name": "29871",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29871"
                },
                {
                  "name": "29910",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29910"
                },
                {
                  "name": "USN-609-1",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-609-1"
                },
                {
                  "name": "openoffice-quattropro-bo(41863)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41863"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2007-5745",
        "datePublished": "2008-04-17T17:00:00.000Z",
        "dateReserved": "2007-10-31T00:00:00.000Z",
        "dateUpdated": "2024-08-07T15:39:13.807Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2007-5746 (GCVE-0-2007-5746)

    Vulnerability from nvd – Published: 2008-04-17 17:00 – Updated: 2024-08-07 15:39
    VLAI
    Summary
    Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an EMF file with a crafted EMR_STRETCHBLT record, which triggers a heap-based buffer overflow.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/29913 third-party-advisoryx_refsource_SECUNIA
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.redhat.com/support/errata/RHSA-2008-01… vendor-advisoryx_refsource_REDHAT
    http://secunia.com/advisories/29852 third-party-advisoryx_refsource_SECUNIA
    http://www.novell.com/linux/security/advisories/2… vendor-advisoryx_refsource_SUSE
    http://secunia.com/advisories/29864 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/29844 third-party-advisoryx_refsource_SECUNIA
    http://security.gentoo.org/glsa/glsa-200805-16.xml vendor-advisoryx_refsource_GENTOO
    http://secunia.com/advisories/30100 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/29987 third-party-advisoryx_refsource_SECUNIA
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.openoffice.org/security/cves/CVE-2007-… x_refsource_CONFIRM
    http://www.openoffice.org/security/cves/CVE-2007-… x_refsource_CONFIRM
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.debian.org/security/2008/dsa-1547 vendor-advisoryx_refsource_DEBIAN
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://www.vupen.com/english/advisories/2008/1253… vdb-entryx_refsource_VUPEN
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    http://www.redhat.com/support/errata/RHSA-2008-01… vendor-advisoryx_refsource_REDHAT
    http://www.vupen.com/english/advisories/2008/1375… vdb-entryx_refsource_VUPEN
    http://www.openoffice.org/security/bulletin.html x_refsource_CONFIRM
    http://secunia.com/advisories/30179 third-party-advisoryx_refsource_SECUNIA
    http://www.openoffice.org/security/cves/CVE-2007-… x_refsource_CONFIRM
    http://www.securityfocus.com/bid/28819 vdb-entryx_refsource_BID
    http://secunia.com/advisories/29871 third-party-advisoryx_refsource_SECUNIA
    http://labs.idefense.com/intelligence/vulnerabili… third-party-advisoryx_refsource_IDEFENSE
    http://secunia.com/advisories/29910 third-party-advisoryx_refsource_SECUNIA
    http://www.ubuntu.com/usn/usn-609-1 vendor-advisoryx_refsource_UBUNTU
    http://www.securitytracker.com/id?1019892 vdb-entryx_refsource_SECTRACK
    Date Public
    2008-04-17 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T15:39:13.741Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "231661",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-231661-1"
              },
              {
                "name": "29913",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29913"
              },
              {
                "name": "MDVSA-2008:090",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:090"
              },
              {
                "name": "RHSA-2008:0175",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0175.html"
              },
              {
                "name": "29852",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29852"
              },
              {
                "name": "SUSE-SA:2008:023",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://www.novell.com/linux/security/advisories/2008_23_openoffice.html"
              },
              {
                "name": "29864",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29864"
              },
              {
                "name": "29844",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29844"
              },
              {
                "name": "GLSA-200805-16",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-200805-16.xml"
              },
              {
                "name": "30100",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30100"
              },
              {
                "name": "29987",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29987"
              },
              {
                "name": "MDVSA-2008:095",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:095"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2007-4770.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2007-5746.html"
              },
              {
                "name": "oval:org.mitre.oval:def:10249",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10249"
              },
              {
                "name": "DSA-1547",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2008/dsa-1547"
              },
              {
                "name": "openoffice-emf-bo(41861)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41861"
              },
              {
                "name": "ADV-2008-1253",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/1253/references"
              },
              {
                "name": "FEDORA-2008-3251",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html"
              },
              {
                "name": "RHSA-2008:0176",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0176.html"
              },
              {
                "name": "ADV-2008-1375",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/1375/references"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/bulletin.html"
              },
              {
                "name": "30179",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30179"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2007-5745.html"
              },
              {
                "name": "28819",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/28819"
              },
              {
                "name": "29871",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29871"
              },
              {
                "name": "20080417 Multiple Vendor OpenOffice EMF EMR_BITBLT Record Integer Overflow Vulnerability",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_IDEFENSE",
                  "x_transferred"
                ],
                "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=692"
              },
              {
                "name": "29910",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/29910"
              },
              {
                "name": "USN-609-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-609-1"
              },
              {
                "name": "1019892",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1019892"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2008-04-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an EMF file with a crafted EMR_STRETCHBLT record, which triggers a heap-based buffer overflow."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-28T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "231661",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-231661-1"
            },
            {
              "name": "29913",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29913"
            },
            {
              "name": "MDVSA-2008:090",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:090"
            },
            {
              "name": "RHSA-2008:0175",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0175.html"
            },
            {
              "name": "29852",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29852"
            },
            {
              "name": "SUSE-SA:2008:023",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://www.novell.com/linux/security/advisories/2008_23_openoffice.html"
            },
            {
              "name": "29864",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29864"
            },
            {
              "name": "29844",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29844"
            },
            {
              "name": "GLSA-200805-16",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-200805-16.xml"
            },
            {
              "name": "30100",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30100"
            },
            {
              "name": "29987",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29987"
            },
            {
              "name": "MDVSA-2008:095",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:095"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2007-4770.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2007-5746.html"
            },
            {
              "name": "oval:org.mitre.oval:def:10249",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10249"
            },
            {
              "name": "DSA-1547",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2008/dsa-1547"
            },
            {
              "name": "openoffice-emf-bo(41861)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41861"
            },
            {
              "name": "ADV-2008-1253",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/1253/references"
            },
            {
              "name": "FEDORA-2008-3251",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html"
            },
            {
              "name": "RHSA-2008:0176",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0176.html"
            },
            {
              "name": "ADV-2008-1375",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/1375/references"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/bulletin.html"
            },
            {
              "name": "30179",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30179"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2007-5745.html"
            },
            {
              "name": "28819",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/28819"
            },
            {
              "name": "29871",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29871"
            },
            {
              "name": "20080417 Multiple Vendor OpenOffice EMF EMR_BITBLT Record Integer Overflow Vulnerability",
              "tags": [
                "third-party-advisory",
                "x_refsource_IDEFENSE"
              ],
              "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=692"
            },
            {
              "name": "29910",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/29910"
            },
            {
              "name": "USN-609-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-609-1"
            },
            {
              "name": "1019892",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1019892"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2007-5746",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an EMF file with a crafted EMR_STRETCHBLT record, which triggers a heap-based buffer overflow."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "231661",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-231661-1"
                },
                {
                  "name": "29913",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29913"
                },
                {
                  "name": "MDVSA-2008:090",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:090"
                },
                {
                  "name": "RHSA-2008:0175",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2008-0175.html"
                },
                {
                  "name": "29852",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29852"
                },
                {
                  "name": "SUSE-SA:2008:023",
                  "refsource": "SUSE",
                  "url": "http://www.novell.com/linux/security/advisories/2008_23_openoffice.html"
                },
                {
                  "name": "29864",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29864"
                },
                {
                  "name": "29844",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29844"
                },
                {
                  "name": "GLSA-200805-16",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-200805-16.xml"
                },
                {
                  "name": "30100",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30100"
                },
                {
                  "name": "29987",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29987"
                },
                {
                  "name": "MDVSA-2008:095",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:095"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2007-4770.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2007-4770.html"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2007-5746.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2007-5746.html"
                },
                {
                  "name": "oval:org.mitre.oval:def:10249",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10249"
                },
                {
                  "name": "DSA-1547",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2008/dsa-1547"
                },
                {
                  "name": "openoffice-emf-bo(41861)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41861"
                },
                {
                  "name": "ADV-2008-1253",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/1253/references"
                },
                {
                  "name": "FEDORA-2008-3251",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html"
                },
                {
                  "name": "RHSA-2008:0176",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2008-0176.html"
                },
                {
                  "name": "ADV-2008-1375",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/1375/references"
                },
                {
                  "name": "http://www.openoffice.org/security/bulletin.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/bulletin.html"
                },
                {
                  "name": "30179",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30179"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2007-5745.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2007-5745.html"
                },
                {
                  "name": "28819",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/28819"
                },
                {
                  "name": "29871",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29871"
                },
                {
                  "name": "20080417 Multiple Vendor OpenOffice EMF EMR_BITBLT Record Integer Overflow Vulnerability",
                  "refsource": "IDEFENSE",
                  "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=692"
                },
                {
                  "name": "29910",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/29910"
                },
                {
                  "name": "USN-609-1",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-609-1"
                },
                {
                  "name": "1019892",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1019892"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2007-5746",
        "datePublished": "2008-04-17T17:00:00.000Z",
        "dateReserved": "2007-10-31T00:00:00.000Z",
        "dateUpdated": "2024-08-07T15:39:13.741Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2010-2936 (GCVE-0-2010-2936)

    Vulnerability from cvelistv5 – Published: 2010-08-25 19:00 – Updated: 2024-08-07 02:46
    VLAI
    Summary
    Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://secunia.com/advisories/40775 third-party-advisoryx_refsource_SECUNIA
    http://www.openoffice.org/servlets/ReadMsg?list=d… mailing-listx_refsource_MLIST
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.vupen.com/english/advisories/2010/2003 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/60799 third-party-advisoryx_refsource_SECUNIA
    http://www.securitytracker.com/id?1024976 vdb-entryx_refsource_SECTRACK
    http://www.gentoo.org/security/en/glsa/glsa-20140… vendor-advisoryx_refsource_GENTOO
    http://www.vupen.com/english/advisories/2011/0150 vdb-entryx_refsource_VUPEN
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://secunia.com/advisories/42927 third-party-advisoryx_refsource_SECUNIA
    http://www.redhat.com/support/errata/RHSA-2010-06… vendor-advisoryx_refsource_REDHAT
    http://www.vupen.com/english/advisories/2011/0230 vdb-entryx_refsource_VUPEN
    http://www.vupen.com/english/advisories/2010/2149 vdb-entryx_refsource_VUPEN
    http://www.openwall.com/lists/oss-security/2010/08/11/1 mailing-listx_refsource_MLIST
    http://www.vupen.com/english/advisories/2010/2228 vdb-entryx_refsource_VUPEN
    http://www.openoffice.org/security/cves/CVE-2010-… x_refsource_CONFIRM
    https://bugzilla.redhat.com/show_bug.cgi?id=622529#c6 x_refsource_CONFIRM
    http://secunia.com/advisories/41235 third-party-advisoryx_refsource_SECUNIA
    http://ubuntu.com/usn/usn-1056-1 vendor-advisoryx_refsource_UBUNTU
    https://bugzilla.redhat.com/show_bug.cgi?id=622555 x_refsource_CONFIRM
    http://www.vupen.com/english/advisories/2011/0279 vdb-entryx_refsource_VUPEN
    http://www.securitytracker.com/id?1024352 vdb-entryx_refsource_SECTRACK
    http://secunia.com/advisories/43105 third-party-advisoryx_refsource_SECUNIA
    http://securityevaluators.com/files/papers/CrashA… x_refsource_MISC
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.debian.org/security/2010/dsa-2099 vendor-advisoryx_refsource_DEBIAN
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.oracle.com/technetwork/topics/security… x_refsource_CONFIRM
    http://secunia.com/advisories/41052 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2010/2905 vdb-entryx_refsource_VUPEN
    http://www.openwall.com/lists/oss-security/2010/08/11/4 mailing-listx_refsource_MLIST
    Date Public
    2010-08-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T02:46:48.696Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "40775",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/40775"
              },
              {
                "name": "[dev] 20100806 Two exploitable OpenOffice.org bugs!",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/servlets/ReadMsg?list=dev\u0026msgNo=27690"
              },
              {
                "name": "MDVSA-2010:221",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:221"
              },
              {
                "name": "ADV-2010-2003",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2003"
              },
              {
                "name": "60799",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/60799"
              },
              {
                "name": "1024976",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1024976"
              },
              {
                "name": "GLSA-201408-19",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
              },
              {
                "name": "ADV-2011-0150",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0150"
              },
              {
                "name": "oval:org.mitre.oval:def:12144",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12144"
              },
              {
                "name": "42927",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/42927"
              },
              {
                "name": "RHSA-2010:0643",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2010-0643.html"
              },
              {
                "name": "ADV-2011-0230",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0230"
              },
              {
                "name": "ADV-2010-2149",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2149"
              },
              {
                "name": "[oss-security] 20100811 CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2010/08/11/1"
              },
              {
                "name": "ADV-2010-2228",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2228"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2010-2935_CVE-2010-2936.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=622529#c6"
              },
              {
                "name": "41235",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/41235"
              },
              {
                "name": "USN-1056-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://ubuntu.com/usn/usn-1056-1"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=622555"
              },
              {
                "name": "ADV-2011-0279",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0279"
              },
              {
                "name": "1024352",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1024352"
              },
              {
                "name": "43105",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/43105"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://securityevaluators.com/files/papers/CrashAnalysis.pdf"
              },
              {
                "name": "SUSE-SR:2010:024",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html"
              },
              {
                "name": "DSA-2099",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2010/dsa-2099"
              },
              {
                "name": "SUSE-SR:2010:019",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html"
              },
              {
                "name": "41052",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/41052"
              },
              {
                "name": "ADV-2010-2905",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2905"
              },
              {
                "name": "[oss-security] 20100811 Re: CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2010/08/11/4"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2010-08-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-18T12:57:01.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "name": "40775",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/40775"
            },
            {
              "name": "[dev] 20100806 Two exploitable OpenOffice.org bugs!",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openoffice.org/servlets/ReadMsg?list=dev\u0026msgNo=27690"
            },
            {
              "name": "MDVSA-2010:221",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:221"
            },
            {
              "name": "ADV-2010-2003",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2003"
            },
            {
              "name": "60799",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/60799"
            },
            {
              "name": "1024976",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1024976"
            },
            {
              "name": "GLSA-201408-19",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
            },
            {
              "name": "ADV-2011-0150",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0150"
            },
            {
              "name": "oval:org.mitre.oval:def:12144",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12144"
            },
            {
              "name": "42927",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/42927"
            },
            {
              "name": "RHSA-2010:0643",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2010-0643.html"
            },
            {
              "name": "ADV-2011-0230",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0230"
            },
            {
              "name": "ADV-2010-2149",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2149"
            },
            {
              "name": "[oss-security] 20100811 CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2010/08/11/1"
            },
            {
              "name": "ADV-2010-2228",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2228"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2010-2935_CVE-2010-2936.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=622529#c6"
            },
            {
              "name": "41235",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/41235"
            },
            {
              "name": "USN-1056-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://ubuntu.com/usn/usn-1056-1"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=622555"
            },
            {
              "name": "ADV-2011-0279",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0279"
            },
            {
              "name": "1024352",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1024352"
            },
            {
              "name": "43105",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/43105"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://securityevaluators.com/files/papers/CrashAnalysis.pdf"
            },
            {
              "name": "SUSE-SR:2010:024",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html"
            },
            {
              "name": "DSA-2099",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2010/dsa-2099"
            },
            {
              "name": "SUSE-SR:2010:019",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html"
            },
            {
              "name": "41052",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/41052"
            },
            {
              "name": "ADV-2010-2905",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2905"
            },
            {
              "name": "[oss-security] 20100811 Re: CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2010/08/11/4"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2010-2936",
        "datePublished": "2010-08-25T19:00:00.000Z",
        "dateReserved": "2010-08-04T00:00:00.000Z",
        "dateUpdated": "2024-08-07T02:46:48.696Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2010-2935 (GCVE-0-2010-2935)

    Vulnerability from cvelistv5 – Published: 2010-08-25 19:00 – Updated: 2024-08-07 02:46
    VLAI
    Summary
    simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an "integer truncation error."
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://secunia.com/advisories/40775 third-party-advisoryx_refsource_SECUNIA
    http://www.openoffice.org/servlets/ReadMsg?list=d… mailing-listx_refsource_MLIST
    https://bugzilla.redhat.com/show_bug.cgi?id=622529 x_refsource_CONFIRM
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.vupen.com/english/advisories/2010/2003 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/60799 third-party-advisoryx_refsource_SECUNIA
    http://www.securitytracker.com/id?1024976 vdb-entryx_refsource_SECTRACK
    http://www.gentoo.org/security/en/glsa/glsa-20140… vendor-advisoryx_refsource_GENTOO
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.vupen.com/english/advisories/2011/0150 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/42927 third-party-advisoryx_refsource_SECUNIA
    http://www.redhat.com/support/errata/RHSA-2010-06… vendor-advisoryx_refsource_REDHAT
    http://www.vupen.com/english/advisories/2011/0230 vdb-entryx_refsource_VUPEN
    http://www.vupen.com/english/advisories/2010/2149 vdb-entryx_refsource_VUPEN
    http://www.openwall.com/lists/oss-security/2010/08/11/1 mailing-listx_refsource_MLIST
    http://www.vupen.com/english/advisories/2010/2228 vdb-entryx_refsource_VUPEN
    http://www.openoffice.org/security/cves/CVE-2010-… x_refsource_CONFIRM
    http://secunia.com/advisories/41235 third-party-advisoryx_refsource_SECUNIA
    http://ubuntu.com/usn/usn-1056-1 vendor-advisoryx_refsource_UBUNTU
    http://www.vupen.com/english/advisories/2011/0279 vdb-entryx_refsource_VUPEN
    http://www.securitytracker.com/id?1024352 vdb-entryx_refsource_SECTRACK
    http://secunia.com/advisories/43105 third-party-advisoryx_refsource_SECUNIA
    http://securityevaluators.com/files/papers/CrashA… x_refsource_MISC
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.debian.org/security/2010/dsa-2099 vendor-advisoryx_refsource_DEBIAN
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.oracle.com/technetwork/topics/security… x_refsource_CONFIRM
    http://secunia.com/advisories/41052 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2010/2905 vdb-entryx_refsource_VUPEN
    http://www.openwall.com/lists/oss-security/2010/08/11/4 mailing-listx_refsource_MLIST
    Date Public
    2010-08-06 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T02:46:48.941Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "40775",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/40775"
              },
              {
                "name": "[dev] 20100806 Two exploitable OpenOffice.org bugs!",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/servlets/ReadMsg?list=dev\u0026msgNo=27690"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=622529"
              },
              {
                "name": "MDVSA-2010:221",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:221"
              },
              {
                "name": "ADV-2010-2003",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2003"
              },
              {
                "name": "60799",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/60799"
              },
              {
                "name": "1024976",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1024976"
              },
              {
                "name": "GLSA-201408-19",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
              },
              {
                "name": "oval:org.mitre.oval:def:12063",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12063"
              },
              {
                "name": "ADV-2011-0150",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0150"
              },
              {
                "name": "42927",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/42927"
              },
              {
                "name": "RHSA-2010:0643",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2010-0643.html"
              },
              {
                "name": "ADV-2011-0230",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0230"
              },
              {
                "name": "ADV-2010-2149",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2149"
              },
              {
                "name": "[oss-security] 20100811 CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2010/08/11/1"
              },
              {
                "name": "ADV-2010-2228",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2228"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2010-2935_CVE-2010-2936.html"
              },
              {
                "name": "41235",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/41235"
              },
              {
                "name": "USN-1056-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://ubuntu.com/usn/usn-1056-1"
              },
              {
                "name": "ADV-2011-0279",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2011/0279"
              },
              {
                "name": "1024352",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1024352"
              },
              {
                "name": "43105",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/43105"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://securityevaluators.com/files/papers/CrashAnalysis.pdf"
              },
              {
                "name": "SUSE-SR:2010:024",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html"
              },
              {
                "name": "DSA-2099",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2010/dsa-2099"
              },
              {
                "name": "SUSE-SR:2010:019",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html"
              },
              {
                "name": "41052",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/41052"
              },
              {
                "name": "ADV-2010-2905",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2010/2905"
              },
              {
                "name": "[oss-security] 20100811 Re: CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2010/08/11/4"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2010-08-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an \"integer truncation error.\""
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-18T12:57:01.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "name": "40775",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/40775"
            },
            {
              "name": "[dev] 20100806 Two exploitable OpenOffice.org bugs!",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openoffice.org/servlets/ReadMsg?list=dev\u0026msgNo=27690"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=622529"
            },
            {
              "name": "MDVSA-2010:221",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:221"
            },
            {
              "name": "ADV-2010-2003",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2003"
            },
            {
              "name": "60799",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/60799"
            },
            {
              "name": "1024976",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1024976"
            },
            {
              "name": "GLSA-201408-19",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
            },
            {
              "name": "oval:org.mitre.oval:def:12063",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12063"
            },
            {
              "name": "ADV-2011-0150",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0150"
            },
            {
              "name": "42927",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/42927"
            },
            {
              "name": "RHSA-2010:0643",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2010-0643.html"
            },
            {
              "name": "ADV-2011-0230",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0230"
            },
            {
              "name": "ADV-2010-2149",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2149"
            },
            {
              "name": "[oss-security] 20100811 CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2010/08/11/1"
            },
            {
              "name": "ADV-2010-2228",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2228"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2010-2935_CVE-2010-2936.html"
            },
            {
              "name": "41235",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/41235"
            },
            {
              "name": "USN-1056-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://ubuntu.com/usn/usn-1056-1"
            },
            {
              "name": "ADV-2011-0279",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2011/0279"
            },
            {
              "name": "1024352",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1024352"
            },
            {
              "name": "43105",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/43105"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://securityevaluators.com/files/papers/CrashAnalysis.pdf"
            },
            {
              "name": "SUSE-SR:2010:024",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html"
            },
            {
              "name": "DSA-2099",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2010/dsa-2099"
            },
            {
              "name": "SUSE-SR:2010:019",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html"
            },
            {
              "name": "41052",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/41052"
            },
            {
              "name": "ADV-2010-2905",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2010/2905"
            },
            {
              "name": "[oss-security] 20100811 Re: CVE Request -- OpenOffice.org [two ids]: 1, integer truncation error 2, short integer overflow",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2010/08/11/4"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2010-2935",
        "datePublished": "2010-08-25T19:00:00.000Z",
        "dateReserved": "2010-08-04T00:00:00.000Z",
        "dateUpdated": "2024-08-07T02:46:48.941Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-3570 (GCVE-0-2009-3570)

    Vulnerability from cvelistv5 – Published: 2009-10-06 20:19 – Updated: 2024-08-07 06:31
    VLAI
    Summary
    Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9. NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.securityfocus.com/bid/36285 vdb-entryx_refsource_BID
    http://secunia.com/advisories/35036 third-party-advisoryx_refsource_SECUNIA
    http://www.securitytracker.com/id?1022828 vdb-entryx_refsource_SECTRACK
    http://intevydis.com/vd-list.shtml x_refsource_MISC
    Date Public
    2009-09-04 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T06:31:10.433Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "36285",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/36285"
              },
              {
                "name": "35036",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/35036"
              },
              {
                "name": "1022828",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1022828"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://intevydis.com/vd-list.shtml"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-09-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9.  NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2014-10-20T13:57:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "36285",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/36285"
            },
            {
              "name": "35036",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/35036"
            },
            {
              "name": "1022828",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1022828"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://intevydis.com/vd-list.shtml"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2009-3570",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9.  NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "36285",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/36285"
                },
                {
                  "name": "35036",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/35036"
                },
                {
                  "name": "1022828",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1022828"
                },
                {
                  "name": "http://intevydis.com/vd-list.shtml",
                  "refsource": "MISC",
                  "url": "http://intevydis.com/vd-list.shtml"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2009-3570",
        "datePublished": "2009-10-06T20:19:00.000Z",
        "dateReserved": "2009-10-06T00:00:00.000Z",
        "dateUpdated": "2024-08-07T06:31:10.433Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-3571 (GCVE-0-2009-3571)

    Vulnerability from cvelistv5 – Published: 2009-10-06 20:19 – Updated: 2024-08-07 06:31
    VLAI
    Summary
    Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side exploit." NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.securityfocus.com/bid/36285 vdb-entryx_refsource_BID
    http://www.securitytracker.com/id?1022832 vdb-entryx_refsource_SECTRACK
    http://secunia.com/advisories/35036 third-party-advisoryx_refsource_SECUNIA
    http://intevydis.com/vd-list.shtml x_refsource_MISC
    Date Public
    2009-09-04 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T06:31:10.630Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "36285",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/36285"
              },
              {
                "name": "1022832",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1022832"
              },
              {
                "name": "35036",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/35036"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://intevydis.com/vd-list.shtml"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-09-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka \"Client-side exploit.\" NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2014-10-20T13:57:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "36285",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/36285"
            },
            {
              "name": "1022832",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1022832"
            },
            {
              "name": "35036",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/35036"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://intevydis.com/vd-list.shtml"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2009-3571",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka \"Client-side exploit.\" NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "36285",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/36285"
                },
                {
                  "name": "1022832",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1022832"
                },
                {
                  "name": "35036",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/35036"
                },
                {
                  "name": "http://intevydis.com/vd-list.shtml",
                  "refsource": "MISC",
                  "url": "http://intevydis.com/vd-list.shtml"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2009-3571",
        "datePublished": "2009-10-06T20:19:00.000Z",
        "dateReserved": "2009-10-06T00:00:00.000Z",
        "dateUpdated": "2024-08-07T06:31:10.630Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-0201 (GCVE-0-2009-0201)

    Vulnerability from cvelistv5 – Published: 2009-09-02 17:00 – Updated: 2024-08-07 04:24
    VLAI
    Summary
    Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to "table parsing."
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.openoffice.org/security/cves/CVE-2009-… x_refsource_CONFIRM
    http://secunia.com/advisories/60799 third-party-advisoryx_refsource_SECUNIA
    http://www.gentoo.org/security/en/glsa/glsa-20140… vendor-advisoryx_refsource_GENTOO
    http://development.openoffice.org/releases/3.1.1.html x_refsource_MISC
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.securitytracker.com/id?1022798 vdb-entryx_refsource_SECTRACK
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://www.securityfocus.com/archive/1/506195/100… mailing-listx_refsource_BUGTRAQ
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.debian.org/security/2009/dsa-1880 vendor-advisoryx_refsource_DEBIAN
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://secunia.com/secunia_research/2009-27/ x_refsource_MISC
    http://secunia.com/advisories/35036 third-party-advisoryx_refsource_SECUNIA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/36750 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/bid/36200 vdb-entryx_refsource_BID
    http://www.vupen.com/english/advisories/2009/2490 vdb-entryx_refsource_VUPEN
    Date Public
    2009-09-01 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T04:24:18.137Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html"
              },
              {
                "name": "60799",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/60799"
              },
              {
                "name": "GLSA-201408-19",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://development.openoffice.org/releases/3.1.1.html"
              },
              {
                "name": "MDVSA-2010:105",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:105"
              },
              {
                "name": "1022798",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1022798"
              },
              {
                "name": "MDVSA-2010:091",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:091"
              },
              {
                "name": "MDVSA-2010:035",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:035"
              },
              {
                "name": "1020715",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1"
              },
              {
                "name": "20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Buffer Overflow",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/506195/100/0/threaded"
              },
              {
                "name": "SUSE-SR:2009:015",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"
              },
              {
                "name": "DSA-1880",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2009/dsa-1880"
              },
              {
                "name": "oval:org.mitre.oval:def:10726",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10726"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://secunia.com/secunia_research/2009-27/"
              },
              {
                "name": "35036",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/35036"
              },
              {
                "name": "263508",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1"
              },
              {
                "name": "36750",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/36750"
              },
              {
                "name": "36200",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/36200"
              },
              {
                "name": "ADV-2009-2490",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2009/2490"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-09-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to \"table parsing.\""
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-11T19:57:01.000Z",
            "orgId": "44d08088-2bea-4760-83a6-1e9be26b15ab",
            "shortName": "flexera"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html"
            },
            {
              "name": "60799",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/60799"
            },
            {
              "name": "GLSA-201408-19",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://development.openoffice.org/releases/3.1.1.html"
            },
            {
              "name": "MDVSA-2010:105",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:105"
            },
            {
              "name": "1022798",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1022798"
            },
            {
              "name": "MDVSA-2010:091",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:091"
            },
            {
              "name": "MDVSA-2010:035",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:035"
            },
            {
              "name": "1020715",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1"
            },
            {
              "name": "20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Buffer Overflow",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/506195/100/0/threaded"
            },
            {
              "name": "SUSE-SR:2009:015",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"
            },
            {
              "name": "DSA-1880",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2009/dsa-1880"
            },
            {
              "name": "oval:org.mitre.oval:def:10726",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10726"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://secunia.com/secunia_research/2009-27/"
            },
            {
              "name": "35036",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/35036"
            },
            {
              "name": "263508",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1"
            },
            {
              "name": "36750",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/36750"
            },
            {
              "name": "36200",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/36200"
            },
            {
              "name": "ADV-2009-2490",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2009/2490"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "PSIRT-CNA@flexerasoftware.com",
              "ID": "CVE-2009-0201",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to \"table parsing.\""
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html"
                },
                {
                  "name": "60799",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/60799"
                },
                {
                  "name": "GLSA-201408-19",
                  "refsource": "GENTOO",
                  "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
                },
                {
                  "name": "http://development.openoffice.org/releases/3.1.1.html",
                  "refsource": "MISC",
                  "url": "http://development.openoffice.org/releases/3.1.1.html"
                },
                {
                  "name": "MDVSA-2010:105",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:105"
                },
                {
                  "name": "1022798",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1022798"
                },
                {
                  "name": "MDVSA-2010:091",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:091"
                },
                {
                  "name": "MDVSA-2010:035",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:035"
                },
                {
                  "name": "1020715",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1"
                },
                {
                  "name": "20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Buffer Overflow",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/506195/100/0/threaded"
                },
                {
                  "name": "SUSE-SR:2009:015",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"
                },
                {
                  "name": "DSA-1880",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2009/dsa-1880"
                },
                {
                  "name": "oval:org.mitre.oval:def:10726",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10726"
                },
                {
                  "name": "http://secunia.com/secunia_research/2009-27/",
                  "refsource": "MISC",
                  "url": "http://secunia.com/secunia_research/2009-27/"
                },
                {
                  "name": "35036",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/35036"
                },
                {
                  "name": "263508",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1"
                },
                {
                  "name": "36750",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/36750"
                },
                {
                  "name": "36200",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/36200"
                },
                {
                  "name": "ADV-2009-2490",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2009/2490"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "44d08088-2bea-4760-83a6-1e9be26b15ab",
        "assignerShortName": "flexera",
        "cveId": "CVE-2009-0201",
        "datePublished": "2009-09-02T17:00:00.000Z",
        "dateReserved": "2009-01-20T00:00:00.000Z",
        "dateUpdated": "2024-08-07T04:24:18.137Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-0200 (GCVE-0-2009-0200)

    Vulnerability from cvelistv5 – Published: 2009-09-02 17:00 – Updated: 2024-08-07 04:24
    VLAI
    Summary
    Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.openoffice.org/security/cves/CVE-2009-… x_refsource_CONFIRM
    http://secunia.com/advisories/60799 third-party-advisoryx_refsource_SECUNIA
    http://www.gentoo.org/security/en/glsa/glsa-20140… vendor-advisoryx_refsource_GENTOO
    http://development.openoffice.org/releases/3.1.1.html x_refsource_MISC
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://secunia.com/secunia_research/2009-26/ x_refsource_MISC
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://www.debian.org/security/2009/dsa-1880 vendor-advisoryx_refsource_DEBIAN
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://secunia.com/advisories/35036 third-party-advisoryx_refsource_SECUNIA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://secunia.com/advisories/36750 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/archive/1/506194/100… mailing-listx_refsource_BUGTRAQ
    http://www.securityfocus.com/bid/36200 vdb-entryx_refsource_BID
    http://www.vupen.com/english/advisories/2009/2490 vdb-entryx_refsource_VUPEN
    Date Public
    2009-09-01 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T04:24:18.284Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html"
              },
              {
                "name": "60799",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/60799"
              },
              {
                "name": "GLSA-201408-19",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://development.openoffice.org/releases/3.1.1.html"
              },
              {
                "name": "MDVSA-2010:105",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:105"
              },
              {
                "name": "MDVSA-2010:091",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:091"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://secunia.com/secunia_research/2009-26/"
              },
              {
                "name": "MDVSA-2010:035",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:035"
              },
              {
                "name": "1020715",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1"
              },
              {
                "name": "SUSE-SR:2009:015",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"
              },
              {
                "name": "DSA-1880",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2009/dsa-1880"
              },
              {
                "name": "oval:org.mitre.oval:def:10881",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10881"
              },
              {
                "name": "35036",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/35036"
              },
              {
                "name": "263508",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1"
              },
              {
                "name": "36750",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/36750"
              },
              {
                "name": "20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Integer Underflow",
                "tags": [
                  "mailing-list",
                  "x_refsource_BUGTRAQ",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/archive/1/506194/100/0/threaded"
              },
              {
                "name": "36200",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/36200"
              },
              {
                "name": "ADV-2009-2490",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2009/2490"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-09-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-10-11T19:57:01.000Z",
            "orgId": "44d08088-2bea-4760-83a6-1e9be26b15ab",
            "shortName": "flexera"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html"
            },
            {
              "name": "60799",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/60799"
            },
            {
              "name": "GLSA-201408-19",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://development.openoffice.org/releases/3.1.1.html"
            },
            {
              "name": "MDVSA-2010:105",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:105"
            },
            {
              "name": "MDVSA-2010:091",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:091"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://secunia.com/secunia_research/2009-26/"
            },
            {
              "name": "MDVSA-2010:035",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:035"
            },
            {
              "name": "1020715",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1"
            },
            {
              "name": "SUSE-SR:2009:015",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"
            },
            {
              "name": "DSA-1880",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2009/dsa-1880"
            },
            {
              "name": "oval:org.mitre.oval:def:10881",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10881"
            },
            {
              "name": "35036",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/35036"
            },
            {
              "name": "263508",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1"
            },
            {
              "name": "36750",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/36750"
            },
            {
              "name": "20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Integer Underflow",
              "tags": [
                "mailing-list",
                "x_refsource_BUGTRAQ"
              ],
              "url": "http://www.securityfocus.com/archive/1/506194/100/0/threaded"
            },
            {
              "name": "36200",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/36200"
            },
            {
              "name": "ADV-2009-2490",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2009/2490"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "PSIRT-CNA@flexerasoftware.com",
              "ID": "CVE-2009-0200",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html"
                },
                {
                  "name": "60799",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/60799"
                },
                {
                  "name": "GLSA-201408-19",
                  "refsource": "GENTOO",
                  "url": "http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml"
                },
                {
                  "name": "http://development.openoffice.org/releases/3.1.1.html",
                  "refsource": "MISC",
                  "url": "http://development.openoffice.org/releases/3.1.1.html"
                },
                {
                  "name": "MDVSA-2010:105",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:105"
                },
                {
                  "name": "MDVSA-2010:091",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:091"
                },
                {
                  "name": "http://secunia.com/secunia_research/2009-26/",
                  "refsource": "MISC",
                  "url": "http://secunia.com/secunia_research/2009-26/"
                },
                {
                  "name": "MDVSA-2010:035",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:035"
                },
                {
                  "name": "1020715",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1"
                },
                {
                  "name": "SUSE-SR:2009:015",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html"
                },
                {
                  "name": "DSA-1880",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2009/dsa-1880"
                },
                {
                  "name": "oval:org.mitre.oval:def:10881",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10881"
                },
                {
                  "name": "35036",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/35036"
                },
                {
                  "name": "263508",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1"
                },
                {
                  "name": "36750",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/36750"
                },
                {
                  "name": "20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Integer Underflow",
                  "refsource": "BUGTRAQ",
                  "url": "http://www.securityfocus.com/archive/1/506194/100/0/threaded"
                },
                {
                  "name": "36200",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/36200"
                },
                {
                  "name": "ADV-2009-2490",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2009/2490"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "44d08088-2bea-4760-83a6-1e9be26b15ab",
        "assignerShortName": "flexera",
        "cveId": "CVE-2009-0200",
        "datePublished": "2009-09-02T17:00:00.000Z",
        "dateReserved": "2009-01-20T00:00:00.000Z",
        "dateUpdated": "2024-08-07T04:24:18.284Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2009-0259 (GCVE-0-2009-0259)

    Vulnerability from cvelistv5 – Published: 2009-01-22 23:00 – Updated: 2024-08-07 04:24
    VLAI
    Summary
    The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Date Public
    2009-01-21 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T04:24:18.478Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "6560",
                "tags": [
                  "exploit",
                  "x_refsource_EXPLOIT-DB",
                  "x_transferred"
                ],
                "url": "https://www.exploit-db.com/exploits/6560"
              },
              {
                "name": "33383",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/33383"
              },
              {
                "name": "openoffice-wordprocessor-code-execution(48213)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48213"
              },
              {
                "name": "[oss-security] 20090121 CVE Request -- openoffice.org (CVE-2008-4841)",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2009/01/21/9"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://milw0rm.com/sploits/2008-crash.doc.rar"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2009-01-21T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-28T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "6560",
              "tags": [
                "exploit",
                "x_refsource_EXPLOIT-DB"
              ],
              "url": "https://www.exploit-db.com/exploits/6560"
            },
            {
              "name": "33383",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/33383"
            },
            {
              "name": "openoffice-wordprocessor-code-execution(48213)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48213"
            },
            {
              "name": "[oss-security] 20090121 CVE Request -- openoffice.org (CVE-2008-4841)",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2009/01/21/9"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://milw0rm.com/sploits/2008-crash.doc.rar"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2009-0259",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "6560",
                  "refsource": "EXPLOIT-DB",
                  "url": "https://www.exploit-db.com/exploits/6560"
                },
                {
                  "name": "33383",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/33383"
                },
                {
                  "name": "openoffice-wordprocessor-code-execution(48213)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48213"
                },
                {
                  "name": "[oss-security] 20090121 CVE Request -- openoffice.org (CVE-2008-4841)",
                  "refsource": "MLIST",
                  "url": "http://www.openwall.com/lists/oss-security/2009/01/21/9"
                },
                {
                  "name": "http://milw0rm.com/sploits/2008-crash.doc.rar",
                  "refsource": "MISC",
                  "url": "http://milw0rm.com/sploits/2008-crash.doc.rar"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2009-0259",
        "datePublished": "2009-01-22T23:00:00.000Z",
        "dateReserved": "2009-01-22T00:00:00.000Z",
        "dateUpdated": "2024-08-07T04:24:18.478Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2008-4937 (GCVE-0-2008-4937)

    Vulnerability from cvelistv5 – Published: 2008-11-05 14:51 – Updated: 2024-08-07 10:31
    VLAI
    Summary
    senddoc in OpenOffice.org (OOo) 2.4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/log.obr.##### temporary file.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.ubuntu.com/usn/usn-677-2 vendor-advisoryx_refsource_UBUNTU
    http://secunia.com/advisories/32856 third-party-advisoryx_refsource_SECUNIA
    http://bugs.debian.org/496361 x_refsource_CONFIRM
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://www.securityfocus.com/bid/30925 vdb-entryx_refsource_BID
    http://www.openwall.com/lists/oss-security/2008/10/30/2 mailing-listx_refsource_MLIST
    https://bugs.gentoo.org/show_bug.cgi?id=235770 x_refsource_CONFIRM
    http://uvw.ru/report.lenny.txt x_refsource_MISC
    http://www.ubuntu.com/usn/usn-677-1 vendor-advisoryx_refsource_UBUNTU
    http://security.gentoo.org/glsa/glsa-200812-13.xml vendor-advisoryx_refsource_GENTOO
    http://dev.gentoo.org/~rbu/security/debiantemp/op… x_refsource_CONFIRM
    https://bugs.gentoo.org/235824 x_refsource_CONFIRM
    http://secunia.com/advisories/33140 third-party-advisoryx_refsource_SECUNIA
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    Date Public
    2008-08-11 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T10:31:28.348Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "USN-677-2",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-677-2"
              },
              {
                "name": "32856",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32856"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://bugs.debian.org/496361"
              },
              {
                "name": "openoffice-senddoc-symlink(44829)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44829"
              },
              {
                "name": "30925",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/30925"
              },
              {
                "name": "[oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2008/10/30/2"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugs.gentoo.org/show_bug.cgi?id=235770"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://uvw.ru/report.lenny.txt"
              },
              {
                "name": "USN-677-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-677-1"
              },
              {
                "name": "GLSA-200812-13",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://dev.gentoo.org/~rbu/security/debiantemp/openoffice.org-common"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugs.gentoo.org/235824"
              },
              {
                "name": "33140",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/33140"
              },
              {
                "name": "MDVSA-2009:070",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:070"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2008-08-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "senddoc in OpenOffice.org (OOo) 2.4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/log.obr.##### temporary file."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-08-07T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "USN-677-2",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-677-2"
            },
            {
              "name": "32856",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32856"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://bugs.debian.org/496361"
            },
            {
              "name": "openoffice-senddoc-symlink(44829)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44829"
            },
            {
              "name": "30925",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/30925"
            },
            {
              "name": "[oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "http://www.openwall.com/lists/oss-security/2008/10/30/2"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugs.gentoo.org/show_bug.cgi?id=235770"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://uvw.ru/report.lenny.txt"
            },
            {
              "name": "USN-677-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-677-1"
            },
            {
              "name": "GLSA-200812-13",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://dev.gentoo.org/~rbu/security/debiantemp/openoffice.org-common"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugs.gentoo.org/235824"
            },
            {
              "name": "33140",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/33140"
            },
            {
              "name": "MDVSA-2009:070",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:070"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2008-4937",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "senddoc in OpenOffice.org (OOo) 2.4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/log.obr.##### temporary file."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "USN-677-2",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-677-2"
                },
                {
                  "name": "32856",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32856"
                },
                {
                  "name": "http://bugs.debian.org/496361",
                  "refsource": "CONFIRM",
                  "url": "http://bugs.debian.org/496361"
                },
                {
                  "name": "openoffice-senddoc-symlink(44829)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44829"
                },
                {
                  "name": "30925",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/30925"
                },
                {
                  "name": "[oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire",
                  "refsource": "MLIST",
                  "url": "http://www.openwall.com/lists/oss-security/2008/10/30/2"
                },
                {
                  "name": "https://bugs.gentoo.org/show_bug.cgi?id=235770",
                  "refsource": "CONFIRM",
                  "url": "https://bugs.gentoo.org/show_bug.cgi?id=235770"
                },
                {
                  "name": "http://uvw.ru/report.lenny.txt",
                  "refsource": "MISC",
                  "url": "http://uvw.ru/report.lenny.txt"
                },
                {
                  "name": "USN-677-1",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-677-1"
                },
                {
                  "name": "GLSA-200812-13",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
                },
                {
                  "name": "http://dev.gentoo.org/~rbu/security/debiantemp/openoffice.org-common",
                  "refsource": "CONFIRM",
                  "url": "http://dev.gentoo.org/~rbu/security/debiantemp/openoffice.org-common"
                },
                {
                  "name": "https://bugs.gentoo.org/235824",
                  "refsource": "CONFIRM",
                  "url": "https://bugs.gentoo.org/235824"
                },
                {
                  "name": "33140",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/33140"
                },
                {
                  "name": "MDVSA-2009:070",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:070"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2008-4937",
        "datePublished": "2008-11-05T14:51:00.000Z",
        "dateReserved": "2008-11-05T00:00:00.000Z",
        "dateUpdated": "2024-08-07T10:31:28.348Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2008-2238 (GCVE-0-2008-2238)

    Vulnerability from cvelistv5 – Published: 2008-10-30 19:19 – Updated: 2024-08-07 08:49
    VLAI
    Summary
    Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.ubuntu.com/usn/usn-677-2 vendor-advisoryx_refsource_UBUNTU
    http://secunia.com/advisories/32856 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/bid/31962 vdb-entryx_refsource_BID
    http://labs.idefense.com/intelligence/vulnerabili… third-party-advisoryx_refsource_IDEFENSE
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://secunia.com/advisories/32461 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2008/3153 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/32419 third-party-advisoryx_refsource_SECUNIA
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    http://secunia.com/advisories/32872 third-party-advisoryx_refsource_SECUNIA
    http://neowiki.neooffice.org/index.php/NeoOffice_… x_refsource_CONFIRM
    http://www.ubuntu.com/usn/usn-677-1 vendor-advisoryx_refsource_UBUNTU
    http://security.gentoo.org/glsa/glsa-200812-13.xml vendor-advisoryx_refsource_GENTOO
    http://secunia.com/advisories/32676 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2008/3103 vdb-entryx_refsource_VUPEN
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://www.vupen.com/english/advisories/2008/2947 vdb-entryx_refsource_VUPEN
    http://secunia.com/advisories/32489 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/32463 third-party-advisoryx_refsource_SECUNIA
    http://www.redhat.com/support/errata/RHSA-2008-09… vendor-advisoryx_refsource_REDHAT
    http://www.openoffice.org/security/cves/CVE-2008-… x_refsource_CONFIRM
    http://www.debian.org/security/2008/dsa-1661 vendor-advisoryx_refsource_DEBIAN
    http://www.securitytracker.com/id?1021121 vdb-entryx_refsource_SECTRACK
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://secunia.com/advisories/33140 third-party-advisoryx_refsource_SECUNIA
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    Date Public
    2008-10-29 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T08:49:58.915Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "USN-677-2",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-677-2"
              },
              {
                "name": "32856",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32856"
              },
              {
                "name": "31962",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/31962"
              },
              {
                "name": "20081031 OpenOffice EMF Record Parsing Multiple Integer Overflow Vulnerabilities",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_IDEFENSE",
                  "x_transferred"
                ],
                "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=750"
              },
              {
                "name": "oval:org.mitre.oval:def:10849",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10849"
              },
              {
                "name": "32461",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32461"
              },
              {
                "name": "ADV-2008-3153",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/3153"
              },
              {
                "name": "32419",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32419"
              },
              {
                "name": "FEDORA-2008-9333",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00923.html"
              },
              {
                "name": "32872",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32872"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes"
              },
              {
                "name": "USN-677-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-677-1"
              },
              {
                "name": "GLSA-200812-13",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
              },
              {
                "name": "32676",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32676"
              },
              {
                "name": "ADV-2008-3103",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/3103"
              },
              {
                "name": "243226",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-243226-1"
              },
              {
                "name": "ADV-2008-2947",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/2947"
              },
              {
                "name": "32489",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32489"
              },
              {
                "name": "32463",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32463"
              },
              {
                "name": "RHSA-2008:0939",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0939.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2008-2238.html"
              },
              {
                "name": "DSA-1661",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2008/dsa-1661"
              },
              {
                "name": "1021121",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1021121"
              },
              {
                "name": "SUSE-SR:2008:026",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html"
              },
              {
                "name": "33140",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/33140"
              },
              {
                "name": "openoffice-emf-file-bo(46166)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46166"
              },
              {
                "name": "FEDORA-2008-9313",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00905.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2008-10-29T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-28T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "USN-677-2",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-677-2"
            },
            {
              "name": "32856",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32856"
            },
            {
              "name": "31962",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/31962"
            },
            {
              "name": "20081031 OpenOffice EMF Record Parsing Multiple Integer Overflow Vulnerabilities",
              "tags": [
                "third-party-advisory",
                "x_refsource_IDEFENSE"
              ],
              "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=750"
            },
            {
              "name": "oval:org.mitre.oval:def:10849",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10849"
            },
            {
              "name": "32461",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32461"
            },
            {
              "name": "ADV-2008-3153",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/3153"
            },
            {
              "name": "32419",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32419"
            },
            {
              "name": "FEDORA-2008-9333",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00923.html"
            },
            {
              "name": "32872",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32872"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes"
            },
            {
              "name": "USN-677-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-677-1"
            },
            {
              "name": "GLSA-200812-13",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
            },
            {
              "name": "32676",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32676"
            },
            {
              "name": "ADV-2008-3103",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/3103"
            },
            {
              "name": "243226",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-243226-1"
            },
            {
              "name": "ADV-2008-2947",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/2947"
            },
            {
              "name": "32489",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32489"
            },
            {
              "name": "32463",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32463"
            },
            {
              "name": "RHSA-2008:0939",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0939.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2008-2238.html"
            },
            {
              "name": "DSA-1661",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2008/dsa-1661"
            },
            {
              "name": "1021121",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1021121"
            },
            {
              "name": "SUSE-SR:2008:026",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html"
            },
            {
              "name": "33140",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/33140"
            },
            {
              "name": "openoffice-emf-file-bo(46166)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46166"
            },
            {
              "name": "FEDORA-2008-9313",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00905.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2008-2238",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "USN-677-2",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-677-2"
                },
                {
                  "name": "32856",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32856"
                },
                {
                  "name": "31962",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/31962"
                },
                {
                  "name": "20081031 OpenOffice EMF Record Parsing Multiple Integer Overflow Vulnerabilities",
                  "refsource": "IDEFENSE",
                  "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=750"
                },
                {
                  "name": "oval:org.mitre.oval:def:10849",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10849"
                },
                {
                  "name": "32461",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32461"
                },
                {
                  "name": "ADV-2008-3153",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/3153"
                },
                {
                  "name": "32419",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32419"
                },
                {
                  "name": "FEDORA-2008-9333",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00923.html"
                },
                {
                  "name": "32872",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32872"
                },
                {
                  "name": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes",
                  "refsource": "CONFIRM",
                  "url": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes"
                },
                {
                  "name": "USN-677-1",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-677-1"
                },
                {
                  "name": "GLSA-200812-13",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
                },
                {
                  "name": "32676",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32676"
                },
                {
                  "name": "ADV-2008-3103",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/3103"
                },
                {
                  "name": "243226",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-243226-1"
                },
                {
                  "name": "ADV-2008-2947",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/2947"
                },
                {
                  "name": "32489",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32489"
                },
                {
                  "name": "32463",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32463"
                },
                {
                  "name": "RHSA-2008:0939",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2008-0939.html"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2008-2238.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2008-2238.html"
                },
                {
                  "name": "DSA-1661",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2008/dsa-1661"
                },
                {
                  "name": "1021121",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1021121"
                },
                {
                  "name": "SUSE-SR:2008:026",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html"
                },
                {
                  "name": "33140",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/33140"
                },
                {
                  "name": "openoffice-emf-file-bo(46166)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46166"
                },
                {
                  "name": "FEDORA-2008-9313",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00905.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2008-2238",
        "datePublished": "2008-10-30T19:19:00.000Z",
        "dateReserved": "2008-05-16T00:00:00.000Z",
        "dateUpdated": "2024-08-07T08:49:58.915Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2008-2237 (GCVE-0-2008-2237)

    Vulnerability from cvelistv5 – Published: 2008-10-30 19:19 – Updated: 2024-08-07 08:49
    VLAI
    Summary
    Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associated with a StarOffice/StarSuite document.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://www.ubuntu.com/usn/usn-677-2 vendor-advisoryx_refsource_UBUNTU
    http://secunia.com/advisories/32856 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/bid/31962 vdb-entryx_refsource_BID
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://secunia.com/advisories/32461 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/32419 third-party-advisoryx_refsource_SECUNIA
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    http://secunia.com/advisories/32872 third-party-advisoryx_refsource_SECUNIA
    http://neowiki.neooffice.org/index.php/NeoOffice_… x_refsource_CONFIRM
    http://www.ubuntu.com/usn/usn-677-1 vendor-advisoryx_refsource_UBUNTU
    http://security.gentoo.org/glsa/glsa-200812-13.xml vendor-advisoryx_refsource_GENTOO
    http://secunia.com/advisories/32676 third-party-advisoryx_refsource_SECUNIA
    http://www.vupen.com/english/advisories/2008/3103 vdb-entryx_refsource_VUPEN
    http://www.vupen.com/english/advisories/2008/2947 vdb-entryx_refsource_VUPEN
    http://www.openoffice.org/security/cves/CVE-2008-… x_refsource_CONFIRM
    http://secunia.com/advisories/32489 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/32463 third-party-advisoryx_refsource_SECUNIA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    http://www.securitytracker.com/id?1021120 vdb-entryx_refsource_SECTRACK
    http://www.redhat.com/support/errata/RHSA-2008-09… vendor-advisoryx_refsource_REDHAT
    http://www.debian.org/security/2008/dsa-1661 vendor-advisoryx_refsource_DEBIAN
    http://lists.opensuse.org/opensuse-security-annou… vendor-advisoryx_refsource_SUSE
    http://secunia.com/advisories/33140 third-party-advisoryx_refsource_SECUNIA
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    Date Public
    2008-10-29 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T08:49:58.925Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "USN-677-2",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-677-2"
              },
              {
                "name": "32856",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32856"
              },
              {
                "name": "31962",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/31962"
              },
              {
                "name": "openoffice-wmf-bo(46165)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46165"
              },
              {
                "name": "32461",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32461"
              },
              {
                "name": "32419",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32419"
              },
              {
                "name": "oval:org.mitre.oval:def:10784",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10784"
              },
              {
                "name": "FEDORA-2008-9333",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00923.html"
              },
              {
                "name": "32872",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32872"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes"
              },
              {
                "name": "USN-677-1",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_UBUNTU",
                  "x_transferred"
                ],
                "url": "http://www.ubuntu.com/usn/usn-677-1"
              },
              {
                "name": "GLSA-200812-13",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
              },
              {
                "name": "32676",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32676"
              },
              {
                "name": "ADV-2008-3103",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/3103"
              },
              {
                "name": "ADV-2008-2947",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/2947"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2008-2237.html"
              },
              {
                "name": "32489",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32489"
              },
              {
                "name": "32463",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/32463"
              },
              {
                "name": "242627",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-242627-1"
              },
              {
                "name": "1021120",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1021120"
              },
              {
                "name": "RHSA-2008:0939",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0939.html"
              },
              {
                "name": "DSA-1661",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "http://www.debian.org/security/2008/dsa-1661"
              },
              {
                "name": "SUSE-SR:2008:026",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUSE",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html"
              },
              {
                "name": "33140",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/33140"
              },
              {
                "name": "FEDORA-2008-9313",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00905.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2008-10-29T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associated with a StarOffice/StarSuite document."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-28T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "USN-677-2",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-677-2"
            },
            {
              "name": "32856",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32856"
            },
            {
              "name": "31962",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/31962"
            },
            {
              "name": "openoffice-wmf-bo(46165)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46165"
            },
            {
              "name": "32461",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32461"
            },
            {
              "name": "32419",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32419"
            },
            {
              "name": "oval:org.mitre.oval:def:10784",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10784"
            },
            {
              "name": "FEDORA-2008-9333",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00923.html"
            },
            {
              "name": "32872",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32872"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes"
            },
            {
              "name": "USN-677-1",
              "tags": [
                "vendor-advisory",
                "x_refsource_UBUNTU"
              ],
              "url": "http://www.ubuntu.com/usn/usn-677-1"
            },
            {
              "name": "GLSA-200812-13",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
            },
            {
              "name": "32676",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32676"
            },
            {
              "name": "ADV-2008-3103",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/3103"
            },
            {
              "name": "ADV-2008-2947",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/2947"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2008-2237.html"
            },
            {
              "name": "32489",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32489"
            },
            {
              "name": "32463",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/32463"
            },
            {
              "name": "242627",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-242627-1"
            },
            {
              "name": "1021120",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1021120"
            },
            {
              "name": "RHSA-2008:0939",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0939.html"
            },
            {
              "name": "DSA-1661",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "http://www.debian.org/security/2008/dsa-1661"
            },
            {
              "name": "SUSE-SR:2008:026",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUSE"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html"
            },
            {
              "name": "33140",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/33140"
            },
            {
              "name": "FEDORA-2008-9313",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00905.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2008-2237",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associated with a StarOffice/StarSuite document."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "USN-677-2",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-677-2"
                },
                {
                  "name": "32856",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32856"
                },
                {
                  "name": "31962",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/31962"
                },
                {
                  "name": "openoffice-wmf-bo(46165)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46165"
                },
                {
                  "name": "32461",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32461"
                },
                {
                  "name": "32419",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32419"
                },
                {
                  "name": "oval:org.mitre.oval:def:10784",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10784"
                },
                {
                  "name": "FEDORA-2008-9333",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00923.html"
                },
                {
                  "name": "32872",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32872"
                },
                {
                  "name": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes",
                  "refsource": "CONFIRM",
                  "url": "http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes"
                },
                {
                  "name": "USN-677-1",
                  "refsource": "UBUNTU",
                  "url": "http://www.ubuntu.com/usn/usn-677-1"
                },
                {
                  "name": "GLSA-200812-13",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-200812-13.xml"
                },
                {
                  "name": "32676",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32676"
                },
                {
                  "name": "ADV-2008-3103",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/3103"
                },
                {
                  "name": "ADV-2008-2947",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/2947"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2008-2237.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2008-2237.html"
                },
                {
                  "name": "32489",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32489"
                },
                {
                  "name": "32463",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/32463"
                },
                {
                  "name": "242627",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-242627-1"
                },
                {
                  "name": "1021120",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1021120"
                },
                {
                  "name": "RHSA-2008:0939",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2008-0939.html"
                },
                {
                  "name": "DSA-1661",
                  "refsource": "DEBIAN",
                  "url": "http://www.debian.org/security/2008/dsa-1661"
                },
                {
                  "name": "SUSE-SR:2008:026",
                  "refsource": "SUSE",
                  "url": "http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html"
                },
                {
                  "name": "33140",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/33140"
                },
                {
                  "name": "FEDORA-2008-9313",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00905.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2008-2237",
        "datePublished": "2008-10-30T19:19:00.000Z",
        "dateReserved": "2008-05-16T00:00:00.000Z",
        "dateUpdated": "2024-08-07T08:49:58.925Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2008-3437 (GCVE-0-2008-3437)

    Vulnerability from cvelistv5 – Published: 2008-08-01 14:00 – Updated: 2024-09-16 19:30
    VLAI
    Summary
    OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T09:37:26.904Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://www.infobyte.com.ar/down/Francisco%20Amato%20-%20evilgrade%20-%20ENG.pdf"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://www.infobyte.com.ar/down/isr-evilgrade-1.0.0.tar.gz"
              },
              {
                "name": "1020583",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1020583"
              },
              {
                "name": "20080728 Tool release: [evilgrade] - Using DNS cache poisoning to exploit poor update implementations",
                "tags": [
                  "mailing-list",
                  "x_refsource_FULLDISC",
                  "x_transferred"
                ],
                "url": "http://archives.neohapsis.com/archives/bugtraq/2008-07/0250.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2008-08-01T14:00:00.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://www.infobyte.com.ar/down/Francisco%20Amato%20-%20evilgrade%20-%20ENG.pdf"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://www.infobyte.com.ar/down/isr-evilgrade-1.0.0.tar.gz"
            },
            {
              "name": "1020583",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://securitytracker.com/id?1020583"
            },
            {
              "name": "20080728 Tool release: [evilgrade] - Using DNS cache poisoning to exploit poor update implementations",
              "tags": [
                "mailing-list",
                "x_refsource_FULLDISC"
              ],
              "url": "http://archives.neohapsis.com/archives/bugtraq/2008-07/0250.html"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2008-3437",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://www.infobyte.com.ar/down/Francisco%20Amato%20-%20evilgrade%20-%20ENG.pdf",
                  "refsource": "MISC",
                  "url": "http://www.infobyte.com.ar/down/Francisco%20Amato%20-%20evilgrade%20-%20ENG.pdf"
                },
                {
                  "name": "http://www.infobyte.com.ar/down/isr-evilgrade-1.0.0.tar.gz",
                  "refsource": "MISC",
                  "url": "http://www.infobyte.com.ar/down/isr-evilgrade-1.0.0.tar.gz"
                },
                {
                  "name": "1020583",
                  "refsource": "SECTRACK",
                  "url": "http://securitytracker.com/id?1020583"
                },
                {
                  "name": "20080728 Tool release: [evilgrade] - Using DNS cache poisoning to exploit poor update implementations",
                  "refsource": "FULLDISC",
                  "url": "http://archives.neohapsis.com/archives/bugtraq/2008-07/0250.html"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2008-3437",
        "datePublished": "2008-08-01T14:00:00.000Z",
        "dateReserved": "2008-08-01T00:00:00.000Z",
        "dateUpdated": "2024-09-16T19:30:38.697Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2008-2366 (GCVE-0-2008-2366)

    Vulnerability from cvelistv5 – Published: 2008-06-16 18:26 – Updated: 2024-08-07 08:58
    VLAI
    Summary
    Untrusted search path vulnerability in a certain Red Hat build script for OpenOffice.org (OOo) 1.1.x on Red Hat Enterprise Linux (RHEL) 3 and 4 allows local users to gain privileges via a malicious library in the current working directory, related to incorrect quoting of the ORIGIN symbol for use in the RPATH library path.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    https://bugzilla.redhat.com/show_bug.cgi?id=450532 x_refsource_CONFIRM
    http://secunia.com/advisories/30633 third-party-advisoryx_refsource_SECUNIA
    http://www.securityfocus.com/bid/29695 vdb-entryx_refsource_BID
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://www.redhat.com/support/errata/RHSA-2008-05… vendor-advisoryx_refsource_REDHAT
    http://securitytracker.com/id?1020278 vdb-entryx_refsource_SECTRACK
    Date Public
    2008-06-12 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T08:58:02.116Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=450532"
              },
              {
                "name": "30633",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30633"
              },
              {
                "name": "29695",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/29695"
              },
              {
                "name": "oval:org.mitre.oval:def:11361",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11361"
              },
              {
                "name": "redhat-ooo-buildscript-code-execution(43322)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43322"
              },
              {
                "name": "RHSA-2008:0538",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0538.html"
              },
              {
                "name": "1020278",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://securitytracker.com/id?1020278"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2008-06-12T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Untrusted search path vulnerability in a certain Red Hat build script for OpenOffice.org (OOo) 1.1.x on Red Hat Enterprise Linux (RHEL) 3 and 4 allows local users to gain privileges via a malicious library in the current working directory, related to incorrect quoting of the ORIGIN symbol for use in the RPATH library path."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-28T12:57:01.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=450532"
            },
            {
              "name": "30633",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30633"
            },
            {
              "name": "29695",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/29695"
            },
            {
              "name": "oval:org.mitre.oval:def:11361",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11361"
            },
            {
              "name": "redhat-ooo-buildscript-code-execution(43322)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43322"
            },
            {
              "name": "RHSA-2008:0538",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0538.html"
            },
            {
              "name": "1020278",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://securitytracker.com/id?1020278"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2008-2366",
        "datePublished": "2008-06-16T18:26:00.000Z",
        "dateReserved": "2008-05-21T00:00:00.000Z",
        "dateUpdated": "2024-08-07T08:58:02.116Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2008-2152 (GCVE-0-2008-2152)

    Vulnerability from cvelistv5 – Published: 2008-06-10 18:00 – Updated: 2024-08-07 08:49
    VLAI
    Summary
    Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.
    Severity
    No CVSS data available.
    CWE
    • n/a
    References
    URL Tags
    http://secunia.com/advisories/30635 third-party-advisoryx_refsource_SECUNIA
    http://www.redhat.com/support/errata/RHSA-2008-05… vendor-advisoryx_refsource_REDHAT
    http://secunia.com/advisories/30633 third-party-advisoryx_refsource_SECUNIA
    http://sunsolve.sun.com/search/document.do?assetk… vendor-advisoryx_refsource_SUNALERT
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    http://www.securitytracker.com/id?1020219 vdb-entryx_refsource_SECTRACK
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    http://security.gentoo.org/glsa/glsa-200807-05.xml vendor-advisoryx_refsource_GENTOO
    http://www.vupen.com/english/advisories/2008/1804… vdb-entryx_refsource_VUPEN
    https://oval.cisecurity.org/repository/search/def… vdb-entrysignaturex_refsource_OVAL
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    http://www.openoffice.org/security/cves/CVE-2008-… x_refsource_CONFIRM
    http://www.redhat.com/support/errata/RHSA-2008-05… vendor-advisoryx_refsource_REDHAT
    http://secunia.com/advisories/30634 third-party-advisoryx_refsource_SECUNIA
    http://secunia.com/advisories/30599 third-party-advisoryx_refsource_SECUNIA
    https://www.redhat.com/archives/fedora-package-an… vendor-advisoryx_refsource_FEDORA
    http://labs.idefense.com/intelligence/vulnerabili… third-party-advisoryx_refsource_IDEFENSE
    https://exchange.xforce.ibmcloud.com/vulnerabilit… vdb-entryx_refsource_XF
    http://www.vupen.com/english/advisories/2008/1773 vdb-entryx_refsource_VUPEN
    http://www.securityfocus.com/bid/29622 vdb-entryx_refsource_BID
    http://secunia.com/advisories/31029 third-party-advisoryx_refsource_SECUNIA
    http://www.mandriva.com/security/advisories?name=… vendor-advisoryx_refsource_MANDRIVA
    Date Public
    2008-06-10 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-07T08:49:58.488Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "30635",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30635"
              },
              {
                "name": "RHSA-2008:0537",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0537.html"
              },
              {
                "name": "30633",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30633"
              },
              {
                "name": "237944",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_SUNALERT",
                  "x_transferred"
                ],
                "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-237944-1"
              },
              {
                "name": "FEDORA-2008-5143",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00385.html"
              },
              {
                "name": "1020219",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id?1020219"
              },
              {
                "name": "FEDORA-2008-5247",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00499.html"
              },
              {
                "name": "GLSA-200807-05",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "http://security.gentoo.org/glsa/glsa-200807-05.xml"
              },
              {
                "name": "ADV-2008-1804",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/1804/references"
              },
              {
                "name": "oval:org.mitre.oval:def:9787",
                "tags": [
                  "vdb-entry",
                  "signature",
                  "x_refsource_OVAL",
                  "x_transferred"
                ],
                "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9787"
              },
              {
                "name": "MDVSA-2008:138",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:138"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.openoffice.org/security/cves/CVE-2008-2152.html"
              },
              {
                "name": "RHSA-2008:0538",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "http://www.redhat.com/support/errata/RHSA-2008-0538.html"
              },
              {
                "name": "30634",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30634"
              },
              {
                "name": "30599",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/30599"
              },
              {
                "name": "FEDORA-2008-5239",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_FEDORA",
                  "x_transferred"
                ],
                "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00473.html"
              },
              {
                "name": "20080610 Multiple Vendor OpenOffice rtl_allocateMemory() Integer Overflow Vulnerability",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_IDEFENSE",
                  "x_transferred"
                ],
                "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=714"
              },
              {
                "name": "openoffice-rtlallocatememory-bo(42957)",
                "tags": [
                  "vdb-entry",
                  "x_refsource_XF",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42957"
              },
              {
                "name": "ADV-2008-1773",
                "tags": [
                  "vdb-entry",
                  "x_refsource_VUPEN",
                  "x_transferred"
                ],
                "url": "http://www.vupen.com/english/advisories/2008/1773"
              },
              {
                "name": "29622",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/29622"
              },
              {
                "name": "31029",
                "tags": [
                  "third-party-advisory",
                  "x_refsource_SECUNIA",
                  "x_transferred"
                ],
                "url": "http://secunia.com/advisories/31029"
              },
              {
                "name": "MDVSA-2008:137",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_MANDRIVA",
                  "x_transferred"
                ],
                "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:137"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "datePublic": "2008-06-10T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-09-28T12:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "30635",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30635"
            },
            {
              "name": "RHSA-2008:0537",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0537.html"
            },
            {
              "name": "30633",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30633"
            },
            {
              "name": "237944",
              "tags": [
                "vendor-advisory",
                "x_refsource_SUNALERT"
              ],
              "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-237944-1"
            },
            {
              "name": "FEDORA-2008-5143",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00385.html"
            },
            {
              "name": "1020219",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id?1020219"
            },
            {
              "name": "FEDORA-2008-5247",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00499.html"
            },
            {
              "name": "GLSA-200807-05",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "http://security.gentoo.org/glsa/glsa-200807-05.xml"
            },
            {
              "name": "ADV-2008-1804",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/1804/references"
            },
            {
              "name": "oval:org.mitre.oval:def:9787",
              "tags": [
                "vdb-entry",
                "signature",
                "x_refsource_OVAL"
              ],
              "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9787"
            },
            {
              "name": "MDVSA-2008:138",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:138"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.openoffice.org/security/cves/CVE-2008-2152.html"
            },
            {
              "name": "RHSA-2008:0538",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "http://www.redhat.com/support/errata/RHSA-2008-0538.html"
            },
            {
              "name": "30634",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30634"
            },
            {
              "name": "30599",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/30599"
            },
            {
              "name": "FEDORA-2008-5239",
              "tags": [
                "vendor-advisory",
                "x_refsource_FEDORA"
              ],
              "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00473.html"
            },
            {
              "name": "20080610 Multiple Vendor OpenOffice rtl_allocateMemory() Integer Overflow Vulnerability",
              "tags": [
                "third-party-advisory",
                "x_refsource_IDEFENSE"
              ],
              "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=714"
            },
            {
              "name": "openoffice-rtlallocatememory-bo(42957)",
              "tags": [
                "vdb-entry",
                "x_refsource_XF"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42957"
            },
            {
              "name": "ADV-2008-1773",
              "tags": [
                "vdb-entry",
                "x_refsource_VUPEN"
              ],
              "url": "http://www.vupen.com/english/advisories/2008/1773"
            },
            {
              "name": "29622",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/29622"
            },
            {
              "name": "31029",
              "tags": [
                "third-party-advisory",
                "x_refsource_SECUNIA"
              ],
              "url": "http://secunia.com/advisories/31029"
            },
            {
              "name": "MDVSA-2008:137",
              "tags": [
                "vendor-advisory",
                "x_refsource_MANDRIVA"
              ],
              "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:137"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-2008-2152",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "30635",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30635"
                },
                {
                  "name": "RHSA-2008:0537",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2008-0537.html"
                },
                {
                  "name": "30633",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30633"
                },
                {
                  "name": "237944",
                  "refsource": "SUNALERT",
                  "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-26-237944-1"
                },
                {
                  "name": "FEDORA-2008-5143",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00385.html"
                },
                {
                  "name": "1020219",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id?1020219"
                },
                {
                  "name": "FEDORA-2008-5247",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00499.html"
                },
                {
                  "name": "GLSA-200807-05",
                  "refsource": "GENTOO",
                  "url": "http://security.gentoo.org/glsa/glsa-200807-05.xml"
                },
                {
                  "name": "ADV-2008-1804",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/1804/references"
                },
                {
                  "name": "oval:org.mitre.oval:def:9787",
                  "refsource": "OVAL",
                  "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9787"
                },
                {
                  "name": "MDVSA-2008:138",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:138"
                },
                {
                  "name": "http://www.openoffice.org/security/cves/CVE-2008-2152.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.openoffice.org/security/cves/CVE-2008-2152.html"
                },
                {
                  "name": "RHSA-2008:0538",
                  "refsource": "REDHAT",
                  "url": "http://www.redhat.com/support/errata/RHSA-2008-0538.html"
                },
                {
                  "name": "30634",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30634"
                },
                {
                  "name": "30599",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/30599"
                },
                {
                  "name": "FEDORA-2008-5239",
                  "refsource": "FEDORA",
                  "url": "https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00473.html"
                },
                {
                  "name": "20080610 Multiple Vendor OpenOffice rtl_allocateMemory() Integer Overflow Vulnerability",
                  "refsource": "IDEFENSE",
                  "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=714"
                },
                {
                  "name": "openoffice-rtlallocatememory-bo(42957)",
                  "refsource": "XF",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42957"
                },
                {
                  "name": "ADV-2008-1773",
                  "refsource": "VUPEN",
                  "url": "http://www.vupen.com/english/advisories/2008/1773"
                },
                {
                  "name": "29622",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/29622"
                },
                {
                  "name": "31029",
                  "refsource": "SECUNIA",
                  "url": "http://secunia.com/advisories/31029"
                },
                {
                  "name": "MDVSA-2008:137",
                  "refsource": "MANDRIVA",
                  "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:137"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2008-2152",
        "datePublished": "2008-06-10T18:00:00.000Z",
        "dateReserved": "2008-05-12T00:00:00.000Z",
        "dateUpdated": "2024-08-07T08:49:58.488Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }