CVE-2009-2139 describes a heap-based buffer overflow in Go-oo 2.x and 3.x (related to OpenOffice.org) that allows remote attackers to execute arbitrary code through a specially crafted EMF file. This vulnerability carries a critical CVSS score of 9.3, indicating a network-based attack with high complexity and complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 94/100 suggests significant potential impact if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:sun:openoffice.org:2.0.0:*:*:*:*:*:*:* | ||
2.0.3CPE matchmatch criteria | cpe:2.3:a:sun:openoffice.org:2.0.3:*:*:*:*:*:*:* | ||
2.0.4CPE matchmatch criteria | cpe:2.3:a:sun:openoffice.org:2.0.4:*:*:*:*:*:*:* | ||
2.1.0CPE matchmatch criteria | cpe:2.3:a:sun:openoffice.org:2.1.0:*:*:*:*:*:*:* | ||
2.2.0CPE matchmatch criteria | cpe:2.3:a:sun:openoffice.org:2.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.