CVE-2015-5213

Modified
Published: 10 Nov 2015, 16:00
Last modified:06 Aug 2024, 06:41

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
6.8 MEDIUM
v2.0 (nvd)
EPSS Score
18.02% MEDIUM
18% probability -4.75%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Nov 2015, 16:00
Published
Vulnerability first disclosed
06 Aug 2024, 06:41
Last Modified
Vulnerability information updated

Description

Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.

CVSS Metrics

  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 18.02% Percentile: 95%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • apacheopenoffice

    ≤ 4.1.1

  • canonicalubuntu_linux

    12.04 | 14.04 | 15.04

  • debiandebian_linux

    7.0 | 8.0

  • libreofficelibreoffice

    ≤ 4.4.4

References (11)