Search CVE reports


Toggle filters

31 – 40 of 81 results


CVE-2010-3454

Medium priority

Some fixes available 4 of 5

Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute...

2 affected packages

libreoffice, openoffice.org

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice
openoffice.org
Show less packages

CVE-2010-3453

Medium priority

Some fixes available 4 of 5

The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft...

2 affected packages

libreoffice, openoffice.org

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice
openoffice.org
Show less packages

CVE-2010-3452

Medium priority

Some fixes available 4 of 5

Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document.

2 affected packages

libreoffice, openoffice.org

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice
openoffice.org
Show less packages

CVE-2010-3451

Medium priority

Some fixes available 4 of 5

Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via malformed tables in an RTF document.

2 affected packages

libreoffice, openoffice.org

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice
openoffice.org
Show less packages

CVE-2010-3450

Medium priority

Some fixes available 4 of 5

Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filter description file, (2) an...

2 affected packages

libreoffice, openoffice.org

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice
openoffice.org
Show less packages

CVE-2010-2936

Low priority

Some fixes available 4 of 6

Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons...

2 affected packages

libreoffice, openoffice.org

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice
openoffice.org
Show less packages

CVE-2010-2935

Low priority

Some fixes available 4 of 6

simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service...

2 affected packages

libreoffice, openoffice.org

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice
openoffice.org
Show less packages

CVE-2010-0395

Medium priority

Some fixes available 4 of 5

OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution...

1 affected package

openoffice.org

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openoffice.org
Show less packages

CVE-2010-0136

Medium priority

Some fixes available 4 of 5

OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.

1 affected package

openoffice.org

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openoffice.org
Show less packages

CVE-2009-3571

Low priority
Ignored

Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side exploit." NOTE: as of 20091005, this...

2 affected packages

openoffice.org, libreoffice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openoffice.org
libreoffice
Show less packages