Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23776
HistoryApr 10, 2020 - 12:35 a.m.

Arbitrary Code Execution

2020-04-1000:35:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.218 Low

EPSS

Percentile

96.5%

openoffice.org is vulnerable to arbitrary code execution. An integer underflow flaw and a boundary error flaw, both possibly leading to a heap-based buffer overflow, were found in the way OpenOffice.org parses certain records in Microsoft Word documents. An attacker could create a specially-crafted Microsoft Word document, which once opened by an unsuspecting user, could cause OpenOffice.org to crash or, potentially, execute arbitrary code with the permissions of the user running OpenOffice.org.

References