← All CVEs

CVE-2007-2834

high · 9.3

Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.

9.3
CVSS
12.0%
EPSS (exploit prob.)
96th
EPSS percentile
2007-09-18
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-190

Affected products

VendorProductAffected versions
apacheopenoffice< 2.3.0
sunstaroffice6.0
sunstaroffice7.0
sunstaroffice8.0
sunstarsuiteall versions
debiandebian_linux3.1
debiandebian_linux4.0
canonicalubuntu_linux6.06
canonicalubuntu_linux6.10
canonicalubuntu_linux7.04

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-2834