MidnightBSD

Advisories for openoffice

CVE-2002-2210 MEDIUM

The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink attack on the USERNAME_autoresponse.conf temporary file.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
openoffice openoffice 1.0.1
CVE-2004-0752 LOW

OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow local users to read or list files of other users.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
openoffice openoffice 1.1.2
CVE-2005-0941 MEDIUM

The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
openoffice openoffice 1.1.3
openoffice openoffice 1.1.4
openoffice openoffice 1.0.2
openoffice openoffice 1.1.1
openoffice openoffice 1.1.0
openoffice openoffice 1.0.1
openoffice openoffice 1.1.2
CVE-2005-4636 MEDIUM

OpenOffice.org 2.0 and earlier, when hyperlinks has been disabled, does not prevent the user from clicking the WWW-browser button in the Hyperlink dialog, which makes it easier for attackers to trick the user into bypassing intended security settings.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
openoffice openoffice 2.0
openoffice openoffice 1.1.3
openoffice openoffice 1.1.4
openoffice openoffice 1.0.2
openoffice openoffice 1.1.1
openoffice openoffice 1.1.5
openoffice openoffice 1.1.0
openoffice openoffice 1.0.1
openoffice openoffice 1.1.2
CVE-2006-2198 HIGH

OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, which is executed without prompting the user.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
openoffice openoffice 1.1.1
openoffice openoffice 1.1.1a
sun staroffice 8.0
openoffice openoffice 1.1.0
openoffice openoffice 1.1.2
openoffice openoffice 2.0.0_rc1
openoffice openoffice 2.0.3_rc4
openoffice openoffice 2.0.0_rc2
openoffice openoffice 2.0.2_rc2
openoffice openoffice 2.0.1
openoffice openoffice 1.1.5
openoffice openoffice 2.0.2_rc3
openoffice openoffice 2.0.3_rc6
sun staroffice 7.0
openoffice openoffice 1.1.3
openoffice openoffice 2.0.0
openoffice openoffice 2.0.2_rc4
openoffice openoffice 2.0.3_rc5
openoffice openoffice 1.1.4
openoffice openoffice 2.0.3_rc3
openoffice openoffice 2.0.2_rc1
openoffice openoffice 1.1.1b
openoffice openoffice 2.0.0_rc3
openoffice openoffice 2.0.2
CVE-2006-2199 HIGH

Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to escape the Java sandbox and conduct unauthorized activities via certain applets in OpenOffice documents.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
sun staroffice 7.0
openoffice openoffice 1.1.3
openoffice openoffice 2.0.0
openoffice openoffice 1.1.1
sun staroffice 8.0
openoffice openoffice 1.1.0
openoffice openoffice 1.1.2
openoffice openoffice 1.1.4
openoffice openoffice 2.0.1
openoffice openoffice 1.1.5
sun staroffice 6.0
openoffice openoffice 2.0.2
CVE-2006-3117 HIGH

Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
sun staroffice 7.0
openoffice openoffice 2.0
openoffice openoffice 1.1.3
openoffice openoffice 2.0.0
openoffice openoffice 1.1.1
sun staroffice 8.0
openoffice openoffice 1.1.0
openoffice openoffice 1.1.2
openoffice openoffice 1.1.4
openoffice openoffice 2.0.1
sun staroffice 6.0
openoffice openoffice 2.0.2
CVE-2006-5870 HIGH

Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
sun staroffice 7.0
sun staroffice 8.0
sun staroffice 6.0
openoffice openoffice *
CVE-2006-6628 MEDIUM

Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted DOC file, as demonstrated by the 12122006-djtest.doc file, a variant of CVE-2006-6561 in a separate codebase.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
openoffice openoffice 2.1
CVE-2007-0238 HIGH

Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5 Patch, allows user-assisted remote attackers to execute arbitrary code via a document with a long Note.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
openoffice openoffice *
CVE-2007-0239 HIGH

OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in a crafted document.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
openoffice openoffice *
CVE-2007-0245 HIGH

Heap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a crafted prtdata tag with a length parameter inconsistency, which causes vtable entries to be overwritten.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
openoffice openoffice *
CVE-2007-4251 MEDIUM

OpenOffice.org (OOo) 2.2 does not properly handle files with multiple extensions, which allows user-assisted remote attackers to cause a denial of service.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
openoffice openoffice 2.2
CVE-2007-4575 HIGH

HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via crafted database documents, related to "exposing static java methods."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
openoffice openoffice 2.2.1
openoffice openoffice 2.0.3_1
openoffice openoffice 2.2
openoffice openoffice 2.1
openoffice openoffice 2.0.3
openoffice openoffice 2.0.4
openoffice openoffice 2.0.1
openoffice openoffice *
openoffice openoffice 2.0beta
openoffice openoffice 2.0.2
CVE-2007-5745 MEDIUM

Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted (1) Attribute and (2) Font Description records.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
openoffice openoffice *
CVE-2007-5746 MEDIUM

Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an EMF file with a crafted EMR_STRETCHBLT record, which triggers a heap-based buffer overflow.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-189,

Products Affected

Vendor Product Version
openoffice openoffice.org 2.3
openoffice openoffice.org 2.2
openoffice openoffice.org 2.0.3
openoffice openoffice.org 2.3.1
openoffice openoffice.org 2.2.1
openoffice openoffice.org 2.1
CVE-2008-0320 HIGH

Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
openoffice openoffice.org 2.3
openoffice openoffice.org *
openoffice openoffice.org 2.2
openoffice openoffice.org 2.0.3
openoffice openoffice.org 2.2.1
openoffice openoffice.org 2.1
CVE-2008-2152 HIGH

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
openoffice openoffice.org 2.3
openoffice openoffice.org 2.4
openoffice openoffice.org 2.2
openoffice openoffice.org 2.0
openoffice openoffice.org 2.1
CVE-2008-2237 HIGH

Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associated with a StarOffice/StarSuite document.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
openoffice openoffice.org 2.3
openoffice openoffice.org *
openoffice openoffice.org 2.4
openoffice openoffice.org 2.2
openoffice openoffice.org 2.3.1
openoffice openoffice.org 2.0.2
openoffice openoffice.org 2.0
openoffice openoffice.org 2.0.3
openoffice openoffice.org 2.4.1
openoffice openoffice.org 2.2.1
openoffice openoffice.org 2.0.4
openoffice openoffice.org 2.1
CVE-2008-2238 HIGH

Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
openoffice openoffice.org 2.3
openoffice openoffice.org *
openoffice openoffice.org 2.4
openoffice openoffice.org 2.2
openoffice openoffice.org 2.3.1
openoffice openoffice.org 2.0.2
openoffice openoffice.org 2.0
openoffice openoffice.org 2.0.3
openoffice openoffice.org 2.4.1
openoffice openoffice.org 2.2.1
openoffice openoffice.org 2.0.4
openoffice openoffice.org 2.1
CVE-2008-2366 MEDIUM

Untrusted search path vulnerability in a certain Red Hat build script for OpenOffice.org (OOo) 1.1.x on Red Hat Enterprise Linux (RHEL) 3 and 4 allows local users to gain privileges via a malicious library in the current working directory, related to incorrect quoting of the ORIGIN symbol for use in the RPATH library path.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-16,

Products Affected

Vendor Product Version
openoffice openoffice 1.1
CVE-2008-3437 HIGH

OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
openoffice openoffice.org 2.0.2
openoffice openoffice.org 1.1.5
openoffice openoffice.org 2.0
openoffice openoffice.org 2.0.3
openoffice openoffice.org 2.0.4
CVE-2008-4937 LOW

senddoc in OpenOffice.org (OOo) 2.4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/log.obr.##### temporary file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-59,

Products Affected

Vendor Product Version
openoffice openoffice.org 2.4.1
CVE-2009-0200 HIGH

Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
openoffice openoffice.org 2.1.154
openoffice openoffice.org 1.1.2
openoffice openoffice.org 638
openoffice openoffice.org 1.1.5
openoffice openoffice.org 643
openoffice openoffice.org 2.2
openoffice openoffice.org 1.9.95
openoffice openoffice.org 1.9.93
openoffice openoffice.org 1.1
openoffice openoffice.org 1.9.104
openoffice openoffice.org 1.9.87
openoffice openoffice.org 1.9.113
openoffice openoffice.org 2.1.152
openoffice openoffice.org 1.9.156
openoffice openoffice.org 641b
openoffice openoffice.org 2.4.1
openoffice openoffice.org 1.0.0
openoffice openoffice.org 2.1
openoffice openoffice.org 633
openoffice openoffice.org 1.9.680
openoffice openoffice.org 1.0-ru
openoffice openoffice.org 638c
openoffice openoffice.org 1.9.122
openoffice openoffice.org 609
openoffice openoffice.org 1.9.91
openoffice openoffice.org 1.9.118
openoffice openoffice.org 1.9.130
openoffice openoffice.org 2.0.3
openoffice openoffice.org 1.1.1
openoffice openoffice.org 1.0.1
openoffice openoffice.org 1.9.84
openoffice openoffice.org 2.3
openoffice openoffice.org 2.4
openoffice openoffice.org 3.01
openoffice openoffice.org 641d
openoffice openoffice.org 2.0.1
openoffice openoffice.org 2.0.4
openoffice openoffice.org 605b
openoffice openoffice.org 614
openoffice openoffice.org 1.0.3.1
openoffice openoffice.org 619
openoffice openoffice.org *
openoffice openoffice.org 2.3.1
openoffice openoffice.org 627
openoffice openoffice.org 1.0.2
openoffice openoffice.org 1.1.3
openoffice openoffice.org 1.9.100
openoffice openoffice.org 2.0.2
openoffice openoffice.org 2.0
openoffice openoffice.org 2.2.1
openoffice openoffice.org 1.1.4
CVE-2009-0201 HIGH

Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to "table parsing."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
openoffice openoffice.org 1.1.2
openoffice openoffice.org 2.3
openoffice openoffice.org *
openoffice openoffice.org 2.4
openoffice openoffice.org 1.1.5
openoffice openoffice.org 2.2
openoffice openoffice.org 2.3.1
openoffice openoffice.org 1.1.3
openoffice openoffice.org 2.0.2
openoffice openoffice.org 2.0
openoffice openoffice.org 2.0.3
openoffice openoffice.org 2.4.1
openoffice openoffice.org 2.2.1
openoffice openoffice.org 2.0.4
openoffice openoffice.org 1.1.4
openoffice openoffice.org 2.1
CVE-2009-0259 HIGH

The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
openoffice openoffice.org 1.1.2
openoffice openoffice.org 1.1.3
openoffice openoffice.org 1.1.5
openoffice openoffice.org 1.1.4
CVE-2009-3570 HIGH

Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9. NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
openoffice openoffice.org *
CVE-2009-3571 HIGH

Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side exploit." NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
openoffice openoffice.org *
CVE-2010-2935 HIGH

simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an "integer truncation error."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
openoffice openoffice.org 3.2.1
CVE-2010-2936 HIGH

Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
openoffice openoffice.org 3.2.1