Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-2935

30
FAUCET Score

CVE-2010-2935 describes a heap-based buffer overflow vulnerability in the Impress module (simpress.bin) of OpenOffice.org versions 2.x and 3.x prior to 3.3. This flaw, stemming from an integer truncation error when handling dictionary property items, allows remote attackers to trigger a denial of service or potentially execute arbitrary code through a specially crafted PowerPoint document. With a CVSS score of 9.3, this vulnerability is considered critical due to its network-based attack vector, medium complexity, and complete compromise of confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
3.2.1CPE matchmatch criteria
cpe:2.3:a:openoffice:openoffice.org:3.2.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
7.09%
Probability of exploitation in next 30 days
EPSS Percentile
93.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0709 is in the 70th percentile among its peer group of 8,915 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

denopatch availablevia llm_extracted
Fixed in: 3.3
View patch
libreofficepatch availablevia llm_extracted
Fixed in: 3.3
View patch
nessuspatch availablevia llm_extracted
Fixed in: 3.3
postgresqlpatch availablevia llm_extracted
Fixed in: 3.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: openoffice.org-0:1.1.2-48.2.0.EL3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: openoffice.org-0:1.1.5-10.6.0.7.EL4.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: openoffice.org2-1:2.0.4-5.7.0.6.1.el4_8.6
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openoffice.org
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: openoffice.org

Vendor Advisories (5)

redhatCVE-2010-2935Important

OpenOffice.Org: Integer truncation error by parsing specially-crafted Microsoft PowerPoint document

Jul 26, 2010
denollm-deno-fdf15146b6be42ea

Security Vulnerability in OpenOffice.org related to PowerPoint document processing

postgresqlllm-postgresql-8b2a1c3e1795fce8

Security Vulnerability in OpenOffice.org related to PowerPoint document processing

libreofficellm-libreoffice-6f0265ac08e05012

Security Vulnerability in OpenOffice.org related to PowerPoint document processing

nessusllm-nessus-80e9e11c9b4bff6d

Security Vulnerability in OpenOffice.org related to PowerPoint document processing

References

lists.opensuse.org / opensuse-security-announce/2010-10/msg00006.html
lists.opensuse.org / opensuse-security-announce/2010-12/msg00006.html
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/40775
Vendor Advisory
secunia.com / advisories/41052
Vendor Advisory
secunia.com / advisories/41235
secunia.com / advisories/42927
secunia.com / advisories/43105
secunia.com / advisories/60799
securityevaluators.com / files/papers/CrashAnalysis.pdf
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12063
ubuntu.com / usn/usn-1056-1
debian.org / security/2010/dsa-2099
gentoo.org / security/en/glsa/glsa-201408-19.xml
mandriva.com / security/advisories
openoffice.org / security/cves/CVE-2010-2935_CVE-2010-2936.html
openoffice.org / servlets/ReadMsg
openwall.com / lists/oss-security/2010/08/11/1
openwall.com / lists/oss-security/2010/08/11/4
oracle.com / technetwork/topics/security/cpujan2011-194091.html
redhat.com / support/errata/RHSA-2010-0643.html
securitytracker.com / id
securitytracker.com / id
vupen.com / english/advisories/2010/2003
Vendor Advisory
vupen.com / english/advisories/2010/2149
Vendor Advisory
vupen.com / english/advisories/2010/2228
vupen.com / english/advisories/2010/2905
vupen.com / english/advisories/2011/0150
vupen.com / english/advisories/2011/0230
vupen.com / english/advisories/2011/0279