Vulnerabilities > Openoffice > Openoffice > High

DATE CVE VULNERABILITY TITLE RISK
2006-06-30 CVE-2006-3117 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."
network
high complexity
openoffice sun CWE-119
7.6
2006-06-30 CVE-2006-2199 Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to escape the Java sandbox and conduct unauthorized activities via certain applets in OpenOffice documents.
network
high complexity
openoffice sun
7.6
2006-06-30 CVE-2006-2198 Permissions, Privileges, and Access Controls vulnerability in multiple products
OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, which is executed without prompting the user.
network
high complexity
openoffice sun CWE-264
7.6
2004-07-07 CVE-2004-0398 Heap Overflow vulnerability in Neon WebDAV Client Library ne_rfc1036_parse Function
Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.
network
low complexity
cadaver neon openoffice subversion
7.5