7.8
CVSSv3

CVE-2021-33035

Published: 23/09/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache openoffice

Recent Articles

Apache OpenOffice can be hijacked by malicious documents, fix still in beta
The Register • Thomas Claburn in San Francisco • 20 Sep 2021

Get our weekly newsletter If you need another reason to try an alternative software suite

Apache OpenOffice (AOO) is currently vulnerable to a remote code execution vulnerability and while the app's source code has been patched, the fix has only been made available as beta software and awaits an official release. That means that most people running the open source office suite, which has been downloaded hundreds of millions of times and was last updated in May, probably have vulnerable versions of the software. On Saturday, September 18, security researcher Eugene Lim revealed detail...