4.3
CVSSv2

CVE-2012-4233

Published: 19/11/2012 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

LibreOffice 3.5.x prior to 3.5.7.2 and 3.6.x prior to 3.6.1, and OpenOffice.org (OOo), allows remote malicious users to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded in a ppt (PowerPoint) file to tllo.dll, or (4) xls (Excel) file to scfiltlo.dll.

Vulnerable Product Search on Vulmon Subscribe to Product

libreoffice libreoffice 3.5.0

libreoffice libreoffice 3.5.3

libreoffice libreoffice 3.5.1

libreoffice libreoffice 3.5.4

libreoffice libreoffice 3.5.

libreoffice libreoffice 3.5.6

libreoffice libreoffice 3.5.6.1

libreoffice libreoffice 3.5.2

libreoffice libreoffice 3.5.5

libreoffice libreoffice 3.5.5.1

sun openoffice.org -

libreoffice libreoffice 3.5.6.2

libreoffice libreoffice 3.5.6.3

libreoffice libreoffice

libreoffice libreoffice 3.5

libreoffice libreoffice 3.5.5.2

libreoffice libreoffice 3.5.5.3

Vendor Advisories

High-Tech Bridge SA Security Research Lab discovered multiple null-pointer dereferences based vulnerabilities in OpenOfficeorg which could cause application crash or even arbitrary code execution using specially crafted files Affected file types are LWP (Lotus Word Pro), ODG, PPT (PowerPoint 2003) and XLS (Excel 2003) For the stable distribution ...