9.3

CVE-2010-0395

OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.

Data is provided by the National Vulnerability Database (NVD)
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version9.04
CanonicalUbuntu Linux Version9.10
CanonicalUbuntu Linux Version10.04 SwEdition-
DebianDebian Linux Version5.0
DebianDebian Linux Version6.0
FedoraprojectFedora Version11
FedoraprojectFedora Version12
FedoraprojectFedora Version13
OpensuseOpensuse Version11.0
OpensuseOpensuse Version11.1
OpensuseOpensuse Version11.2
SuseLinux Enterprise Desktop Version10 Updatesp3
SuseLinux Enterprise Desktop Version11 Update-
ApacheOpenoffice Version >= 2.0.0 < 3.2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 15.7% 0.945
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
http://www.us-cert.gov/cas/techalerts/TA10-287A.html
Third Party Advisory
US Government Resource
http://ubuntu.com/usn/usn-949-1
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=574119
Third Party Advisory
Issue Tracking