Apache Openoffice vulnerabilities

59 known vulnerabilities affecting apache/openoffice.

Total CVEs
59
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH27MEDIUM17

Vulnerabilities

Page 3 of 3
CVE-2012-0037MEDIUMCVSS 6.5v3.3.0v3.4.02012-06-17
CVE-2012-0037 [MEDIUM] CWE-611 CVE-2012-0037: Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice bef Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
nvd
CVE-2010-3452CRITICALCVSS 9.3≥ 2.0.0, < 3.3.02011-01-28
CVE-2010-3452 [CRITICAL] CWE-416 CVE-2010-3452: Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remot Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document.
nvd
CVE-2010-4643CRITICALCVSS 9.3≥ 2.0.0, < 3.3.02011-01-28
CVE-2010-4643 [CRITICAL] CWE-787 CVE-2010-4643: Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote a Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.
nvd
CVE-2010-3454CRITICALCVSS 9.3≥ 2.0.0, < 3.3.02011-01-28
CVE-2010-3454 [CRITICAL] CWE-193 CVE-2010-3454: Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.o Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
nvd
CVE-2010-3450CRITICALCVSS 9.3≥ 2.0.0, < 3.3.02011-01-28
CVE-2010-3450 [CRITICAL] CWE-22 CVE-2010-3450: Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow re Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filter description file, (2) an Extension (aka OXT) file, or unspecified other (3) JAR or (4) ZIP files.
nvd
CVE-2010-3451CRITICALCVSS 9.3≥ 2.0.0, < 3.3.02011-01-28
CVE-2010-3451 [CRITICAL] CWE-416 CVE-2010-3451: Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remot Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via malformed tables in an RTF document.
nvd
CVE-2010-3453CRITICALCVSS 9.3≥ 2.0.0, < 3.3.02011-01-28
CVE-2010-3453 [CRITICAL] CWE-787 CVE-2010-3453: The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3 The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code vi
nvd
CVE-2010-4253CRITICALCVSS 9.3≥ 2.0.0, < 3.3.02011-01-28
CVE-2010-4253 [CRITICAL] CWE-787 CVE-2010-4253: Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote a Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document.
nvd
CVE-2010-3689MEDIUMCVSS 6.9≥ 3.0.0, < 3.3.02011-01-28
CVE-2010-3689 [MEDIUM] CWE-22 CVE-2010-3689: soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
nvd
CVE-2010-4494HIGHCVSS 7.5≥ 2.1.0, ≤ 2.4.3≥ 3.0.0, < 3.3.02010-12-07
CVE-2010-4494 [HIGH] CWE-415 CVE-2010-4494: Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.5 Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
nvd
CVE-2010-4008MEDIUMCVSS 4.3≥ 2.0.0, ≤ 2.4.3≥ 3.0.0, < 3.3.02010-11-17
CVE-2010-4008 [MEDIUM] CWE-119 CVE-2010-4008: libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, an libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
nvd
CVE-2010-0395CRITICALCVSS 9.3≥ 2.0.0, < 3.2.12010-06-10
CVE-2010-0395 [CRITICAL] CVE-2010-0395: OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.
nvd
CVE-2009-2950CRITICALCVSS 9.3fixed in 3.2.02010-02-16
CVE-2009-2950 [CRITICAL] CWE-787 CVE-2009-2950: Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression.
nvd
CVE-2009-3301CRITICALCVSS 9.3fixed in 3.2.02010-02-16
CVE-2009-3301 [CRITICAL] CWE-191 CVE-2009-3301: Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attacke Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.
nvd
CVE-2009-2949CRITICALCVSS 9.3fixed in 3.2.02010-02-16
CVE-2009-2949 [CRITICAL] CWE-190 CVE-2009-2949: Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.
nvd
CVE-2010-0136CRITICALCVSS 9.3v2.0.4v2.4.1+1 more2010-02-16
CVE-2010-0136 [CRITICAL] CWE-77 CVE-2010-0136: OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.
nvd
CVE-2009-3302CRITICALCVSS 9.3fixed in 3.2.02010-02-16
CVE-2009-3302 [CRITICAL] CWE-94 CVE-2009-3302: filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTSetBrc table property modifier in a Word document, related to a "boundary error flaw."
nvd
CVE-2008-3282HIGHCVSS 7.8v2.4.12008-08-29
CVE-2008-3282 [HIGH] CVE-2008-3282: Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory a Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document, related to a "numeric truncation error," a different vulnerability tha
nvd
CVE-2007-2834CRITICALCVSS 9.3fixed in 2.3.02007-09-18
CVE-2007-2834 [CRITICAL] CWE-190 CVE-2007-2834: Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.
nvd