Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-0245

25
FAUCET Score

CVE-2007-0245 describes a heap-based buffer overflow vulnerability in OpenOffice.org versions 2.2.1 and earlier. This flaw allows remote attackers to execute arbitrary code by crafting a malicious RTF file containing an inconsistent prtdata tag, leading to vtable entry overwrites. With a CVSS score of 9.3, this vulnerability is critical, indicating a network-based attack with medium complexity that can result in complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.2.1CPE matchmatch criteria
cpe:2.3:a:openoffice:openoffice:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
6.40%
Probability of exploitation in next 30 days
EPSS Percentile
92.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0640 is in the 67th percentile among its peer group of 8,915 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

debianpatch availablevia nvd_reference
View patch
denopatch availablevia llm_extracted
Fixed in: 2.2.1
View patch
libreofficepatch availablevia llm_extracted
Fixed in: 2.2.1
View patch
nessuspatch availablevia llm_extracted
Fixed in: 2.2.1
postgresqlpatch availablevia llm_extracted
Fixed in: 2.2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: openoffice.org2-1:2.0.4-5.7.0.1.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: openoffice.org-0:1.1.2-39.2.0.EL3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: openoffice.org-1:2.0.4-5.4.17.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: openoffice.org-0:1.1.5-10.6.0.1.EL4
View patch

Vendor Advisories (5)

redhatCVE-2007-0245Important

openoffice.org rtf filter buffer overflow

Jun 12, 2007
denollm-deno-0e9d9f3e69e7a645

Manipulated RTF files can lead to heap overflows and arbitrary code execution

postgresqlllm-postgresql-0a5a1bb25a8b104f

Manipulated RTF files can lead to heap overflows and arbitrary code execution

libreofficellm-libreoffice-b5624ecfe02dac34

Manipulated RTF files can lead to heap overflows and arbitrary code execution

nessusllm-nessus-2671e09e46631b95

Manipulated RTF files can lead to heap overflows and arbitrary code execution

References

patches.sgi.com / support/free/security/advisories/20070602-01-P.asc
osvdb.org / 35378
secunia.com / advisories/25648
Vendor Advisory
secunia.com / advisories/25650
Vendor Advisory
secunia.com / advisories/25673
Vendor Advisory
secunia.com / advisories/25705
Vendor Advisory
secunia.com / advisories/25862
Vendor Advisory
secunia.com / advisories/25894
Vendor Advisory
secunia.com / advisories/25905
Vendor Advisory
secunia.com / advisories/26010
Vendor Advisory
secunia.com / advisories/26022
Vendor Advisory
secunia.com / advisories/26476
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/34843
issues.rpath.com / browse/RPL-1570
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10002
sunsolve.sun.com / search/document.do
sw.openoffice.org / source/browse/sw/sw/source/filter/rtf/swparrtf.cxx
debian.org / security/2007/dsa-1307
Patch
gentoo.org / security/en/glsa/glsa-200707-02.xml
mandriva.com / security/advisories
novell.com / linux/security/advisories/2007_37_openoffice.html
redhat.com / support/errata/RHSA-2007-0406.html
securityfocus.com / archive/1/471274/100/0/threaded
securityfocus.com / bid/24450
securitytracker.com / id
ubuntu.com / usn/usn-482-1
vupen.com / english/advisories/2007/2166
Vendor Advisory
vupen.com / english/advisories/2007/2229
Vendor Advisory