Lucene search

K
cve[email protected]CVE-2015-5214
HistoryNov 10, 2015 - 5:59 p.m.

CVE-2015-5214

2015-11-1017:59:04
CWE-119
web.nvd.nist.gov
66
cve-2015-5214
denial of service
code execution
libreoffice
apache openoffice
memory corruption
application crash
doc file
security vulnerability

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.5%

LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via an index to a non-existent bookmark in a DOC file.

Affected configurations

NVD
Node
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch15.04
OR
debiandebian_linuxMatch7.0
OR
debiandebian_linuxMatch8.0
Node
libreofficelibreofficeRange4.4.5
Node
apacheopenofficeRange4.1.1

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.5%