openoffice records
30 published records for vendor openoffice.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3.3%
- Pre-auth RCE
- 19
- With a fix record
- 70%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-189 Numeric Errors6
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-16 Configuration1
The weakness classes this vendor ships most often: where to look.
CWEAll records
30 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
54Plan | CVE-2008-0320Weaponized | Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) andopenoffice · openoffice.org · CWE-119 | Critical9.3 | — | 56.9% | Apr 17, 2008 |
41Plan | CVE-2007-4575No exploit | HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code openoffice · openoffice · CWE-94 | Critical9.3 | — | 14.3% | Dec 5, 2007 |
40Plan | CVE-2009-3570No exploit | Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in Vopenoffice · openoffice.org | Critical10.0 | — | 1.5% | Oct 6, 2009 |
39Monitor | CVE-2006-5870No exploit | Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; openoffice · openoffice · CWE-189 | Critical9.3 | — | 8.3% | Dec 31, 2006 |
39Monitor | CVE-2009-0259Proof of concept | The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute aopenoffice · openoffice.org · CWE-399 | Critical9.3 | — | 7.5% | Jan 22, 2009 |
39Monitor | CVE-2010-2935No exploit | simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with diopenoffice · openoffice.org · CWE-189 | Critical9.3 | — | 7.1% | Aug 25, 2010 |
39Monitor | CVE-2010-2936No exploit | Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denopenoffice · openoffice.org · CWE-189 | Critical9.3 | — | 7.1% | Aug 25, 2010 |
39Monitor | CVE-2009-0201No exploit | Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to executeopenoffice · openoffice.org · CWE-119 | Critical9.3 | — | 6.7% | Sep 2, 2009 |
39Monitor | CVE-2008-2238No exploit | Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR recordsopenoffice · openoffice.org · CWE-119 | Critical9.3 | — | 6.7% | Oct 30, 2008 |
39Monitor | CVE-2009-0200No exploit | Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitraropenoffice · openoffice.org · CWE-189 | Critical9.3 | — | 6.7% | Sep 2, 2009 |
39Monitor | CVE-2007-0245No exploit | Heap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with aopenoffice · openoffice · CWE-119 | Critical9.3 | — | 6.7% | Jun 12, 2007 |
39Monitor | CVE-2008-2237No exploit | Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF fileopenoffice · openoffice.org · CWE-119 | Critical9.3 | — | 6.1% | Oct 30, 2008 |
39Monitor | CVE-2007-0238No exploit | Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x befopenoffice · openoffice · CWE-119 | Critical9.3 | — | 5.7% | Mar 21, 2007 |
39Monitor | CVE-2008-2152No exploit | Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote aopenoffice · openoffice.org · CWE-189 | Critical9.3 | — | 5.7% | Jun 10, 2008 |
38Monitor | CVE-2007-0239No exploit | OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a preparedopenoffice · openoffice | Critical9.3 | — | 3.5% | Mar 21, 2007 |
37Monitor | CVE-2009-3571No exploit | Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in Vopenoffice · openoffice.org · CWE-119 | Critical9.3 | — | 1.3% | Oct 6, 2009 |
31Monitor | CVE-2006-3117No exploit | Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to exeopenoffice · openoffice · CWE-119 | High7.6 | — | 4.3% | Jun 30, 2006 |
31Monitor | CVE-2006-2199No exploit | Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted aopenoffice · openoffice | High7.6 | — | 3.5% | Jun 30, 2006 |
31Monitor | CVE-2006-2198No exploit | OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities vopenoffice · openoffice · CWE-264 | High7.6 | — | 3.5% | Jun 30, 2006 |
31Monitor | CVE-2008-3437No exploit | OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute openoffice · openoffice.org · CWE-94 | High7.5 | — | 1.9% | Aug 1, 2008 |
28Monitor | CVE-2007-5746No exploit | Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary coopenoffice · openoffice.org · CWE-189 | Medium6.8 | — | 4.6% | Apr 17, 2008 |
28Monitor | CVE-2007-5745No exploit | Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly eopenoffice · openoffice · CWE-119 | Medium6.8 | — | 4.1% | Apr 17, 2008 |
24Monitor | CVE-2002-2210No exploit | The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink attack on the USERNAMEopenoffice · openoffice | Medium6.2 | — | 0.4% | Dec 31, 2002 |
21Monitor | CVE-2005-0941No exploit | The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but proceopenoffice · openoffice | Medium5.1 | — | 4.1% | May 2, 2005 |
18Monitor | CVE-2006-6628Proof of concept | Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a cropenoffice · openoffice | Medium4.3 | — | 3.6% | Dec 18, 2006 |
- CVE-2008-032054Plan
Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and
CriticalCVSS 9.3WeaponizedEPSS 57%openoffice · openoffice.orgApr 17, 2008
- CVE-2007-457541Plan
HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code
CriticalCVSS 9.3No exploitEPSS 14%openoffice · openofficeDec 5, 2007
- CVE-2009-357040Plan
Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in V
CriticalCVSS 10.0No exploitEPSS 2%openoffice · openoffice.orgOct 6, 2009
- CVE-2006-587039Monitor
Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8;
CriticalCVSS 9.3No exploitEPSS 8%openoffice · openofficeDec 31, 2006
- CVE-2009-025939Monitor
The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute a
CriticalCVSS 9.3Proof of conceptEPSS 8%openoffice · openoffice.orgJan 22, 2009
- CVE-2010-293539Monitor
simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with di
CriticalCVSS 9.3No exploitEPSS 7%openoffice · openoffice.orgAug 25, 2010
- CVE-2010-293639Monitor
Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a den
CriticalCVSS 9.3No exploitEPSS 7%openoffice · openoffice.orgAug 25, 2010
- CVE-2009-020139Monitor
Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute
CriticalCVSS 9.3No exploitEPSS 7%openoffice · openoffice.orgSep 2, 2009
- CVE-2008-223839Monitor
Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records
CriticalCVSS 9.3No exploitEPSS 7%openoffice · openoffice.orgOct 30, 2008
- CVE-2009-020039Monitor
Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrar
CriticalCVSS 9.3No exploitEPSS 7%openoffice · openoffice.orgSep 2, 2009
- CVE-2007-024539Monitor
Heap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a
CriticalCVSS 9.3No exploitEPSS 7%openoffice · openofficeJun 12, 2007
- CVE-2008-223739Monitor
Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file
CriticalCVSS 9.3No exploitEPSS 6%openoffice · openoffice.orgOct 30, 2008
- CVE-2007-023839Monitor
Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x bef
CriticalCVSS 9.3No exploitEPSS 6%openoffice · openofficeMar 21, 2007
- CVE-2008-215239Monitor
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote a
CriticalCVSS 9.3No exploitEPSS 6%openoffice · openoffice.orgJun 10, 2008
- CVE-2007-023938Monitor
OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared
CriticalCVSS 9.3No exploitEPSS 3%openoffice · openofficeMar 21, 2007
- CVE-2009-357137Monitor
Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in V
CriticalCVSS 9.3No exploitEPSS 1%openoffice · openoffice.orgOct 6, 2009
- CVE-2006-311731Monitor
Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to exe
HighCVSS 7.6No exploitEPSS 4%openoffice · openofficeJun 30, 2006
- CVE-2006-219931Monitor
Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted a
HighCVSS 7.6No exploitEPSS 3%openoffice · openofficeJun 30, 2006
- CVE-2006-219831Monitor
OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities v
HighCVSS 7.6No exploitEPSS 3%openoffice · openofficeJun 30, 2006
- CVE-2008-343731Monitor
OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute
HighCVSS 7.5No exploitEPSS 2%openoffice · openoffice.orgAug 1, 2008
- CVE-2007-574628Monitor
Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary co
MediumCVSS 6.8No exploitEPSS 5%openoffice · openoffice.orgApr 17, 2008
- CVE-2007-574528Monitor
Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly e
MediumCVSS 6.8No exploitEPSS 4%openoffice · openofficeApr 17, 2008
- CVE-2002-221024Monitor
The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink attack on the USERNAME
MediumCVSS 6.2No exploitEPSS 0%openoffice · openofficeDec 31, 2002
- CVE-2005-094121Monitor
The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but proce
MediumCVSS 5.1No exploitEPSS 4%openoffice · openofficeMay 2, 2005
- CVE-2006-662818Monitor
Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a cr
MediumCVSS 4.3Proof of conceptEPSS 4%openoffice · openofficeDec 18, 2006