Show filters
92 Total Results
Displaying 51-60 of 92
Sort by:
Attacker Value
Unknown
CVE-2010-2935
Disclosure Date: August 25, 2010 (last updated October 04, 2023)
simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an "integer truncation error."
0
Attacker Value
Unknown
CVE-2010-2936
Disclosure Date: August 25, 2010 (last updated October 04, 2023)
Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2010-0395
Disclosure Date: June 10, 2010 (last updated October 04, 2023)
OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.
0
Attacker Value
Unknown
CVE-2009-2950
Disclosure Date: February 16, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression.
0
Attacker Value
Unknown
CVE-2010-0136
Disclosure Date: February 16, 2010 (last updated October 04, 2023)
OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.
0
Attacker Value
Unknown
CVE-2009-3302
Disclosure Date: February 16, 2010 (last updated October 04, 2023)
filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTSetBrc table property modifier in a Word document, related to a "boundary error flaw."
0
Attacker Value
Unknown
CVE-2009-3301
Disclosure Date: February 16, 2010 (last updated October 04, 2023)
Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.
0
Attacker Value
Unknown
CVE-2009-2949
Disclosure Date: February 16, 2010 (last updated October 04, 2023)
Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2009-3569
Disclosure Date: October 06, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side stack overflow exploit." NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
0
Attacker Value
Unknown
CVE-2009-3571
Disclosure Date: October 06, 2009 (last updated October 04, 2023)
Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side exploit." NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
0