Lucene search

K
cve[email protected]CVE-2008-0320
HistoryApr 17, 2008 - 7:05 p.m.

CVE-2008-0320

2008-04-1719:05:00
CWE-119
web.nvd.nist.gov
31
cve-2008-0320
ole importer
denial of service
remote attackers
arbitrary code
buffer overflow
openoffice.org

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

High

0.924 High

EPSS

Percentile

99.0%

Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream.

Affected configurations

NVD
Node
openofficeopenoffice.orgRange≀2.3.1
OR
openofficeopenoffice.orgMatch2.0.3
OR
openofficeopenoffice.orgMatch2.1
OR
openofficeopenoffice.orgMatch2.2
OR
openofficeopenoffice.orgMatch2.2.1
OR
openofficeopenoffice.orgMatch2.3

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

High

0.924 High

EPSS

Percentile

99.0%