9.3
CVSSv2

CVE-2009-2949

Published: 16/02/2010 Updated: 07/02/2022
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) prior to 3.2 allows remote malicious users to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache openoffice

canonical ubuntu linux 8.04

canonical ubuntu linux 8.10

canonical ubuntu linux 9.04

canonical ubuntu linux 9.10

debian debian linux 4.0

debian debian linux 5.0

Vendor Advisories

Synopsis Important: openofficeorg security update Type/Severity Security Advisory: Important Topic Updated openofficeorg packages that correct multiple security issues arenow available for Red Hat Enterprise Linux 3, 4, and 5This update has been rated as having important security impact by the RedHat Sec ...
It was discovered that the XML HMAC signature system did not correctly check certain lengths If an attacker sent a truncated HMAC, it could bypass authentication, leading to potential privilege escalation (CVE-2009-0217) ...
Several vulnerabilities have been discovered in the OpenOfficeorg office suite The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-0136 It was discovered that macro security settings were insufficiently enforced for VBA macros CVE-2009-0217 It was discovered that the W3C XML Signature recomme ...