Vulnerabilities
Vulnerable Software
Openoffice:  >> Openoffice.org  Security Vulnerabilities
OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
CVSS Score
7.5
EPSS Score
0.008
Published
2008-08-01
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.
CVSS Score
9.3
EPSS Score
0.04
Published
2008-06-10
Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an EMF file with a crafted EMR_STRETCHBLT record, which triggers a heap-based buffer overflow.
CVSS Score
6.8
EPSS Score
0.077
Published
2008-04-17
Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream.
CVSS Score
9.3
EPSS Score
0.82
Published
2008-04-17


Contact Us

Shodan ® - All rights reserved