Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-0941

Опубликовано: 02 мая 2005
Источник: nvd
CVSS2: 5.1
EPSS Низкий

Описание

The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openoffice:openoffice:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:openoffice:openoffice:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:openoffice:openoffice:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:openoffice:openoffice:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:openoffice:openoffice:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:openoffice:openoffice:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:openoffice:openoffice:1.1.4:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02726
Низкий

5.1 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 20 лет назад

The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.

redhat
больше 20 лет назад

The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.

debian
больше 20 лет назад

The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 ...

github
больше 3 лет назад

The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.

EPSS

Процентиль: 85%
0.02726
Низкий

5.1 Medium

CVSS2

Дефекты

NVD-CWE-Other