CVE-2010-2936

Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 25 Aug 2010, 19:00
Last modified:07 Aug 2024, 02:46

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.3 HIGH
v2.0 (nvd)
EPSS Score
5.66% LOW
6% probability -2.55%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Aug 2010, 19:00
Published
Vulnerability first disclosed
07 Aug 2024, 02:46
Last Modified
Vulnerability information updated

Description

Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow.

CVSS Metrics

  • v2.0HIGHScore: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 5.66% Percentile: 91%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • openofficeopenoffice.org

    3.2.1

References (31)