CVE-2010-3453 describes an out-of-bounds write vulnerability in OpenOffice.org versions 2.x and 3.x prior to 3.3, specifically within the WW8ListManager function when processing crafted Microsoft Word .DOC files with user-defined list styles. This flaw affects various distributions of OpenOffice.org on Debian and Ubuntu Linux. With a CVSS score of 9.3, this vulnerability is critical, allowing remote attackers to cause a denial of service (application crash) or potentially execute arbitrary code through a medium complexity attack requiring user interaction. Despite its high severity, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 3.3.0CPE matchmatch criteria | cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:* | ||
8.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:* | ||
9.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:* | ||
10.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:* | ||
10.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OpenOffice.org: Heap-based buffer overflow by processing *.doc files with WW8 list styles with specially-crafted count of list levels
Jan 26, 2011Security Vulnerability in OpenOffice.org related to Word document processing
Security Vulnerability in OpenOffice.org related to Word document processing
Security Vulnerability in OpenOffice.org related to Word document processing
Security Vulnerability in OpenOffice.org related to Word document processing