Lucene search

K
cve[email protected]CVE-2010-3453
HistoryJan 28, 2011 - 10:00 p.m.

CVE-2010-3453

2011-01-2822:00:05
CWE-787
web.nvd.nist.gov
89
cve-2010-3453
openoffice.org
oowriter
denial of service
application crash
arbitrary code execution
microsoft word
doc file

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7 High

AI Score

Confidence

High

0.013 Low

EPSS

Percentile

86.2%

The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.

Affected configurations

NVD
Node
apacheopenofficeRange2.0.03.3.0
Node
canonicalubuntu_linuxMatch8.04-
OR
canonicalubuntu_linuxMatch9.10
OR
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch10.10
OR
debiandebian_linuxMatch5.0
OR
debiandebian_linuxMatch6.0

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7 High

AI Score

Confidence

High

0.013 Low

EPSS

Percentile

86.2%