9.3

CVE-2010-3454

Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheOpenoffice Version >= 2.0.0 < 3.3.0
CanonicalUbuntu Linux Version8.04
CanonicalUbuntu Linux Version9.10
CanonicalUbuntu Linux Version10.04
CanonicalUbuntu Linux Version10.10
DebianDebian Linux Version5.0
DebianDebian Linux Version6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.56% 0.924
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-193 Off-by-one Error

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

http://ubuntu.com/usn/usn-1056-1
Third Party Advisory
http://www.securityfocus.com/bid/46031
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1025002
Third Party Advisory
Broken Link
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=640954
Third Party Advisory
Issue Tracking