9.3
CVSSv2

CVE-2010-0136

Published: 16/02/2010 Updated: 07/11/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote malicious users to run arbitrary macros via a crafted document.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache openoffice 2.0.4

apache openoffice 2.4.1

apache openoffice 3.1.1

debian debian linux 5.0

debian debian linux 4.0

canonical ubuntu linux 9.04

canonical ubuntu linux 8.10

canonical ubuntu linux 9.10

canonical ubuntu linux 8.04

Vendor Advisories

It was discovered that the XML HMAC signature system did not correctly check certain lengths If an attacker sent a truncated HMAC, it could bypass authentication, leading to potential privilege escalation (CVE-2009-0217) ...
Several vulnerabilities have been discovered in the OpenOfficeorg office suite The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-0136 It was discovered that macro security settings were insufficiently enforced for VBA macros CVE-2009-0217 It was discovered that the W3C XML Signature recomme ...