← All CVEs

CVE-2010-3450

high · 9.3

Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filter description file, (2) an Extension (aka OXT) file, or unspecified other (3) JAR or (4) ZIP files.

9.3
CVSS
10.7%
EPSS (exploit prob.)
96th
EPSS percentile
2011-01-28
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
apacheopenoffice>= 2.0.0, < 3.3.0
canonicalubuntu_linux8.04
canonicalubuntu_linux9.10
canonicalubuntu_linux10.04
canonicalubuntu_linux10.10
debiandebian_linux5.0
debiandebian_linux6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-3450