Записи openoffice
30 опубликованных записей вендора openoffice.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 3,3 %
- Pre-auth RCE
- 19
- С записью об исправлении
- 70 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-189 Numeric Errors6
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-16 Configuration1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
30 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
54В плане | CVE-2008-0320Готовый эксплойт | Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) andopenoffice · openoffice.org · CWE-119 | Критическая9,3 | — | 56,9 % | 17 апр. 2008 г. |
41В плане | CVE-2007-4575Эксплойта нет | HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code openoffice · openoffice · CWE-94 | Критическая9,3 | — | 14,3 % | 5 дек. 2007 г. |
40В плане | CVE-2009-3570Эксплойта нет | Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in Vopenoffice · openoffice.org | Критическая10,0 | — | 1,5 % | 6 окт. 2009 г. |
39Наблюдать | CVE-2006-5870Эксплойта нет | Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; openoffice · openoffice · CWE-189 | Критическая9,3 | — | 8,3 % | 31 дек. 2006 г. |
39Наблюдать | CVE-2009-0259Proof of concept | The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute aopenoffice · openoffice.org · CWE-399 | Критическая9,3 | — | 7,5 % | 22 янв. 2009 г. |
39Наблюдать | CVE-2010-2935Эксплойта нет | simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with diopenoffice · openoffice.org · CWE-189 | Критическая9,3 | — | 7,1 % | 25 авг. 2010 г. |
39Наблюдать | CVE-2010-2936Эксплойта нет | Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denopenoffice · openoffice.org · CWE-189 | Критическая9,3 | — | 7,1 % | 25 авг. 2010 г. |
39Наблюдать | CVE-2009-0201Эксплойта нет | Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to executeopenoffice · openoffice.org · CWE-119 | Критическая9,3 | — | 6,7 % | 2 сент. 2009 г. |
39Наблюдать | CVE-2008-2238Эксплойта нет | Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR recordsopenoffice · openoffice.org · CWE-119 | Критическая9,3 | — | 6,7 % | 30 окт. 2008 г. |
39Наблюдать | CVE-2009-0200Эксплойта нет | Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitraropenoffice · openoffice.org · CWE-189 | Критическая9,3 | — | 6,7 % | 2 сент. 2009 г. |
39Наблюдать | CVE-2007-0245Эксплойта нет | Heap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with aopenoffice · openoffice · CWE-119 | Критическая9,3 | — | 6,7 % | 12 июн. 2007 г. |
39Наблюдать | CVE-2008-2237Эксплойта нет | Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF fileopenoffice · openoffice.org · CWE-119 | Критическая9,3 | — | 6,1 % | 30 окт. 2008 г. |
39Наблюдать | CVE-2007-0238Эксплойта нет | Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x befopenoffice · openoffice · CWE-119 | Критическая9,3 | — | 5,7 % | 21 мар. 2007 г. |
39Наблюдать | CVE-2008-2152Эксплойта нет | Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote aopenoffice · openoffice.org · CWE-189 | Критическая9,3 | — | 5,7 % | 10 июн. 2008 г. |
38Наблюдать | CVE-2007-0239Эксплойта нет | OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a preparedopenoffice · openoffice | Критическая9,3 | — | 3,5 % | 21 мар. 2007 г. |
37Наблюдать | CVE-2009-3571Эксплойта нет | Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in Vopenoffice · openoffice.org · CWE-119 | Критическая9,3 | — | 1,3 % | 6 окт. 2009 г. |
31Наблюдать | CVE-2006-3117Эксплойта нет | Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to exeopenoffice · openoffice · CWE-119 | Высокая7,6 | — | 4,3 % | 30 июн. 2006 г. |
31Наблюдать | CVE-2006-2199Эксплойта нет | Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted aopenoffice · openoffice | Высокая7,6 | — | 3,5 % | 30 июн. 2006 г. |
31Наблюдать | CVE-2006-2198Эксплойта нет | OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities vopenoffice · openoffice · CWE-264 | Высокая7,6 | — | 3,5 % | 30 июн. 2006 г. |
31Наблюдать | CVE-2008-3437Эксплойта нет | OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute openoffice · openoffice.org · CWE-94 | Высокая7,5 | — | 1,9 % | 1 авг. 2008 г. |
28Наблюдать | CVE-2007-5746Эксплойта нет | Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary coopenoffice · openoffice.org · CWE-189 | Средняя6,8 | — | 4,6 % | 17 апр. 2008 г. |
28Наблюдать | CVE-2007-5745Эксплойта нет | Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly eopenoffice · openoffice · CWE-119 | Средняя6,8 | — | 4,1 % | 17 апр. 2008 г. |
24Наблюдать | CVE-2002-2210Эксплойта нет | The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink attack on the USERNAMEopenoffice · openoffice | Средняя6,2 | — | 0,4 % | 31 дек. 2002 г. |
21Наблюдать | CVE-2005-0941Эксплойта нет | The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but proceopenoffice · openoffice | Средняя5,1 | — | 4,1 % | 2 мая 2005 г. |
18Наблюдать | CVE-2006-6628Proof of concept | Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a cropenoffice · openoffice | Средняя4,3 | — | 3,6 % | 18 дек. 2006 г. |
- CVE-2008-032054В плане
Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and
КритическаяCVSS 9,3Готовый эксплойтEPSS 57 %openoffice · openoffice.org17 апр. 2008 г.
- CVE-2007-457541В плане
HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code
КритическаяCVSS 9,3Эксплойта нетEPSS 14 %openoffice · openoffice5 дек. 2007 г.
- CVE-2009-357040В плане
Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in V
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %openoffice · openoffice.org6 окт. 2009 г.
- CVE-2006-587039Наблюдать
Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8;
КритическаяCVSS 9,3Эксплойта нетEPSS 8 %openoffice · openoffice31 дек. 2006 г.
- CVE-2009-025939Наблюдать
The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute a
КритическаяCVSS 9,3Proof of conceptEPSS 8 %openoffice · openoffice.org22 янв. 2009 г.
- CVE-2010-293539Наблюдать
simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with di
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %openoffice · openoffice.org25 авг. 2010 г.
- CVE-2010-293639Наблюдать
Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a den
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %openoffice · openoffice.org25 авг. 2010 г.
- CVE-2009-020139Наблюдать
Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %openoffice · openoffice.org2 сент. 2009 г.
- CVE-2008-223839Наблюдать
Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %openoffice · openoffice.org30 окт. 2008 г.
- CVE-2009-020039Наблюдать
Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrar
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %openoffice · openoffice.org2 сент. 2009 г.
- CVE-2007-024539Наблюдать
Heap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %openoffice · openoffice12 июн. 2007 г.
- CVE-2008-223739Наблюдать
Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %openoffice · openoffice.org30 окт. 2008 г.
- CVE-2007-023839Наблюдать
Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x bef
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %openoffice · openoffice21 мар. 2007 г.
- CVE-2008-215239Наблюдать
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote a
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %openoffice · openoffice.org10 июн. 2008 г.
- CVE-2007-023938Наблюдать
OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared
КритическаяCVSS 9,3Эксплойта нетEPSS 3 %openoffice · openoffice21 мар. 2007 г.
- CVE-2009-357137Наблюдать
Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in V
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %openoffice · openoffice.org6 окт. 2009 г.
- CVE-2006-311731Наблюдать
Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to exe
ВысокаяCVSS 7,6Эксплойта нетEPSS 4 %openoffice · openoffice30 июн. 2006 г.
- CVE-2006-219931Наблюдать
Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted a
ВысокаяCVSS 7,6Эксплойта нетEPSS 3 %openoffice · openoffice30 июн. 2006 г.
- CVE-2006-219831Наблюдать
OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities v
ВысокаяCVSS 7,6Эксплойта нетEPSS 3 %openoffice · openoffice30 июн. 2006 г.
- CVE-2008-343731Наблюдать
OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openoffice · openoffice.org1 авг. 2008 г.
- CVE-2007-574628Наблюдать
Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary co
СредняяCVSS 6,8Эксплойта нетEPSS 5 %openoffice · openoffice.org17 апр. 2008 г.
- CVE-2007-574528Наблюдать
Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly e
СредняяCVSS 6,8Эксплойта нетEPSS 4 %openoffice · openoffice17 апр. 2008 г.
- CVE-2002-221024Наблюдать
The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink attack on the USERNAME
СредняяCVSS 6,2Эксплойта нетEPSS 0 %openoffice · openoffice31 дек. 2002 г.
- CVE-2005-094121Наблюдать
The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but proce
СредняяCVSS 5,1Эксплойта нетEPSS 4 %openoffice · openoffice2 мая 2005 г.
- CVE-2006-662818Наблюдать
Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a cr
СредняяCVSS 4,3Proof of conceptEPSS 4 %openoffice · openoffice18 дек. 2006 г.