9.3
CVSSv2

CVE-2009-2139

Published: 08/09/2009 Updated: 19/07/2010
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in svtools/source/filter.vcl/wmf/enhwmf.cxx in Go-oo 2.x and 3.x prior to 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allows remote malicious users to execute arbitrary code via a crafted EMF file, a similar issue to CVE-2008-2238.

Vulnerable Product Search on Vulmon Subscribe to Product

sun openoffice.org 2.4.0

sun openoffice.org 2.4.1

sun openoffice.org 2.4.2

sun openoffice.org 3.0.0

sun openoffice.org 2.4.3

sun openoffice.org 2.1.0

sun openoffice.org 2.3.0

sun openoffice.org 2.2.1

sun openoffice.org 2.0.3

sun openoffice.org 2.0.0

sun openoffice.org 2.2.0

sun openoffice.org 2.3.1

sun openoffice.org 2.0.4

Vendor Advisories

Dyon Balding discovered flaws in the way OpenOfficeorg handled tables If a user were tricked into opening a specially crafted Word document, a remote attacker might be able to execute arbitrary code with user privileges (CVE-2009-0200, CVE-2009-0201) ...
Several vulnerabilities have been discovered in the OpenOfficeorg office suite The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-0200 Dyon Balding of Secunia Research has discovered a vulnerability, which can be exploited by opening a specially crafted Microsoft Word document When readi ...