← Vulnerability feed

Vulnerability record · CVE-2000-1156 · published 9 January 2001

CVE-2000-1156: Sun staroffice vulnerability

Sun · Staroffice

StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.

3.6 CVSS 2.0 Low EPSS 0.45% · top 63.0%
3.6CVSS 2.0 base score
0.45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.

AV:L/AC:L/Au:N/C:P/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-1156 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2000-0175Sun staroffice vulnerabilityBuffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.EPSS 2.4%9.3CVE-2007-2834Apache openoffice integer overflow vulnerabilityInteger overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attack…EPSS 12%9.3CVE-2006-5870Openoffice vulnerabilityMultiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow use…EPSS 8.5%7.6CVE-2006-2199Openoffice vulnerabilityUnspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers …EPSS 3.5%7.6CVE-2006-3117Openoffice memory buffer overflow vulnerabilityHeap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbi…EPSS 4.3%7.6CVE-2006-2198Openoffice permissions and access controls vulnerabilityOpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an Ope…EPSS 3.5%5.0CVE-2000-0174Sun staroffice vulnerabilityStarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.EPSS 5.9%4.6CVE-2000-0291Sun staroffice vulnerabilityBuffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a document.EPSS 0.45%

Source: NIST National Vulnerability Database (record CVE-2000-1156), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.