Lucene search

K
nvd[email protected]NVD:CVE-2006-3117
HistoryJun 30, 2006 - 6:05 p.m.

CVE-2006-3117

2006-06-3018:05:00
CWE-119
web.nvd.nist.gov
5

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.011

Percentile

84.1%

Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka “File Format / Buffer Overflow Vulnerability.”

Affected configurations

Nvd
Node
openofficeopenofficeMatch1.1.0
OR
openofficeopenofficeMatch1.1.1
OR
openofficeopenofficeMatch1.1.2
OR
openofficeopenofficeMatch1.1.3
OR
openofficeopenofficeMatch1.1.4
OR
openofficeopenofficeMatch2.0
OR
openofficeopenofficeMatch2.0.0
OR
openofficeopenofficeMatch2.0.1
OR
openofficeopenofficeMatch2.0.2
OR
sunstarofficeMatch6.0
OR
sunstarofficeMatch7.0
OR
sunstarofficeMatch8.0

References

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.011

Percentile

84.1%