CVE-2014-3575 describes a vulnerability in Apache OpenOffice and OpenOffice.org where crafted OLE objects could allow remote attackers to embed arbitrary data during OLE preview generation. This medium-complexity vulnerability (CVSS 4.3) primarily poses a confidentiality risk (CWE-200) by potentially exposing sensitive information, though it does not directly impact integrity or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:* | ||
< 4.1.1CPE matchmatch criteria | cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:* | ||
< 4.2.6CPE matchmatch criteria | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
openoffice: Arbitrary file disclosure via crafted OLE objects
Aug 21, 2014Arbitrary File Disclosure using crafted OLE objects
Arbitrary File Disclosure using crafted OLE objects
Targeted Data Exposure Using Crafted OLE Objects in Apache OpenOffice
Targeted Data Exposure Using Crafted OLE Objects in Apache OpenOffice
Targeted Data Exposure Using Crafted OLE Objects in Apache OpenOffice
Targeted Data Exposure Using Crafted OLE Objects in Apache OpenOffice