Vulnerability Details CVE-2005-0941
The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.028
EPSS Ranking 85.3%
CVSS Severity
CVSS v2 Score 5.1
Products affected by CVE-2005-0941
-
cpe:2.3:a:openoffice:openoffice:1.0.1
-
cpe:2.3:a:openoffice:openoffice:1.0.2
-
cpe:2.3:a:openoffice:openoffice:1.1.0
-
cpe:2.3:a:openoffice:openoffice:1.1.1
-
cpe:2.3:a:openoffice:openoffice:1.1.2
-
cpe:2.3:a:openoffice:openoffice:1.1.3
-
cpe:2.3:a:openoffice:openoffice:1.1.4