7.6
CVSSv2

CVE-2006-3117

Published: 30/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 676
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x prior to 2.0.3 allows user-assisted malicious users to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

openoffice openoffice 1.1.4

openoffice openoffice 2.0

openoffice openoffice 2.0.0

openoffice openoffice 2.0.1

openoffice openoffice 1.1.2

openoffice openoffice 1.1.3

sun staroffice 7.0

sun staroffice 8.0

openoffice openoffice 1.1.0

openoffice openoffice 1.1.1

openoffice openoffice 2.0.2

sun staroffice 6.0

Vendor Advisories

USN-313-1 fixed several vulnerabilities in OpenOffice for Ubuntu 504 and Ubuntu 606 LTS This followup advisory provides the corresponding update for Ubuntu 510 ...
It was possible to embed Basic macros in documents in a way that OpenOfficeorg would not ask for confirmation about executing them By tricking a user into opening a malicious document, this could be exploited to run arbitrary Basic code (including local file access and modification) with the user’s privileges (CVE-2006-2198) ...