CVE-2006-6628
published 2006-12-18CVE-2006-6628: Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted DOC file, as…
PriorityP412medium4.3CVSS 2.0
AVNACMAuNCNINAP
EXPLOIT
EPSS
3.50%
87.7th percentile
Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted DOC file, as demonstrated by the 12122006-djtest.doc file, a variant of CVE-2006-6561 in a separate codebase.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openoffice | openoffice | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gj93-5m6j-gvr2: Integer overflow in OpenOffice
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2006-6628 [CRITICAL] GHSA-gj93-5m6j-gvr2: Integer overflow in OpenOffice
Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted DOC file, as demonstrated by the 12122006-djtest.doc file, a variant of CVE-2006-6561 in a separate codebase.
Red Hat
CVE-2006-6628: Integer overflow in OpenOffice
vendor_redhat·CVSS 9.3
CVE-2006-6628 [CRITICAL] CVE-2006-6628: Integer overflow in OpenOffice
Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted DOC file, as demonstrated by the 12122006-djtest.doc file, a variant of CVE-2006-6561 in a separate codebase.
Statement: Red Hat does not consider this flaw a security issue. This flaw will only crash OpenOffice.org and presents no possibility for arbitrary code execution.
No detection rules found.
No writeups or analysis indexed.
http://securityreason.com/securityalert/2043http://www.milw0rm.com/sploits/12122006-djtest.dochttp://www.securityfocus.com/archive/1/454514/100/0/threadedhttp://www.securityfocus.com/archive/1/454545/100/0/threadedhttp://www.securityfocus.com/archive/1/454722/100/0/threadedhttp://www.securityfocus.com/archive/1/454737/100/0/threadedhttp://www.securityfocus.com/bid/21618http://www.vupen.com/english/advisories/2006/5051http://securityreason.com/securityalert/2043http://www.milw0rm.com/sploits/12122006-djtest.dochttp://www.securityfocus.com/archive/1/454514/100/0/threadedhttp://www.securityfocus.com/archive/1/454545/100/0/threadedhttp://www.securityfocus.com/archive/1/454722/100/0/threadedhttp://www.securityfocus.com/archive/1/454737/100/0/threadedhttp://www.securityfocus.com/bid/21618http://www.vupen.com/english/advisories/2006/5051
2006-12-18
Published