CVE-2010-0136
published 2010-02-16CVE-2010-0136: OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote…
PriorityP349critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
8.13%
94.2th percentile
OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | — | — |
| apache | openoffice | — | — |
| apache | openoffice | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Sun OpenOffice 2.0.4/2.4.1/3.1.1 access control (Nessus ID 44859 / ID 165587)
vuldb·2026-04-30·CVSS 9.3
CVE-2010-0136 [CRITICAL] Sun OpenOffice 2.0.4/2.4.1/3.1.1 access control (Nessus ID 44859 / ID 165587)
A vulnerability was found in Sun OpenOffice 2.0.4/2.4.1/3.1.1. It has been rated as critical. This impacts an unknown function. The manipulation leads to improper access controls.
This vulnerability is listed as CVE-2010-0136. The attack may be initiated remotely. There is no available exploit.
GHSA
GHSA-4g9j-hp5m-7j2p: OpenOffice
ghsa_unreviewed·2022-05-02
CVE-2010-0136 [HIGH] CWE-77 GHSA-4g9j-hp5m-7j2p: OpenOffice
OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.
Ubuntu
OpenOffice.org vulnerabilities
vendor_ubuntu·2010-02-24·CVSS 5.0
CVE-2009-0217 [MEDIUM] OpenOffice.org vulnerabilities
Title: OpenOffice.org vulnerabilities
Summary: OpenOffice.org vulnerabilities
It was discovered that the XML HMAC signature system did not
correctly check certain lengths. If an attacker sent a truncated
HMAC, it could bypass authentication, leading to potential privilege
escalation. (CVE-2009-0217)
Sebastian Apelt and Frank Reißner discovered that OpenOffice did not
correctly import XPM and GIF images. If a user were tricked into opening
a specially crafted image, an attacker could execute arbitrary code with
user privileges. (CVE-2009-2949, CVE-2009-2950)
Nicolas Joly discovered that OpenOffice did not correctly handle
certain Word documents. If a user were tricked into opening a specially
crafted document, an attacker could execute arbitrary code with user
privileges. (CVE-2009-3301
Red Hat
openoffice.org: unenforced VBA macro security settings may lead to arbitrary macro execution
vendor_redhat·2010-02-12·CVSS 9.3
CVE-2010-0136 [CRITICAL] openoffice.org: unenforced VBA macro security settings may lead to arbitrary macro execution
openoffice.org: unenforced VBA macro security settings may lead to arbitrary macro execution
OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.
Statement: Not vulnerable. This issue did not affect the versions of openoffice.org as shipped with Red Hat Enterprise Linux 3, 4, or 5.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.htmlhttp://secunia.com/advisories/38695http://secunia.com/advisories/38921http://securitytracker.com/id?1023588http://www.debian.org/security/2010/dsa-1995http://www.mail-archive.com/debian-openoffice%40lists.debian.org/msg23178.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:221http://www.securityfocus.com/bid/38245http://www.ubuntu.com/usn/USN-903-1http://www.vupen.com/english/advisories/2010/0635http://www.vupen.com/english/advisories/2010/2905http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.htmlhttp://secunia.com/advisories/38695http://secunia.com/advisories/38921http://securitytracker.com/id?1023588http://www.debian.org/security/2010/dsa-1995http://www.mail-archive.com/debian-openoffice%40lists.debian.org/msg23178.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:221http://www.securityfocus.com/bid/38245http://www.ubuntu.com/usn/USN-903-1http://www.vupen.com/english/advisories/2010/0635http://www.vupen.com/english/advisories/2010/2905
2010-02-16
Published