CVE-2010-3453

OpenOffice.org 2.x-3.3 - DoS

Title source: llm

Description

The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.

Scores

EPSS 0.0731
EPSS Percentile 91.5%

Classification

CWE
CWE-787
Status draft

Affected Products (7)

apache/openoffice < 3.3.0
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux
debian/debian_linux

Timeline

Published Jan 28, 2011
Tracked Since Feb 18, 2026