← Vulnerability feed

Vulnerability record · CVE-2006-2198 · published 30 June 2006

CVE-2006-2198: Openoffice permissions and access controls vulnerability

Openoffice · Openoffice

OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, which is executed without prompting the user.

7.6 CVSS 2.0 High EPSS 3.5% · top 11.3% CWE-264 · Permissions and access controls
7.6CVSS 2.0 base score
3.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
58References
23 Sep 2026Last modified by NVD

Description

OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, which is executed without prompting the user.

AV:N/AC:H/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://fedoranews.org/cms/node/2343
http://secunia.com/advisories/20867 Vendor Advisory
http://secunia.com/advisories/20893 Vendor Advisory
http://secunia.com/advisories/20910 Vendor Advisory
http://secunia.com/advisories/20911 Vendor Advisory
http://secunia.com/advisories/20913 Vendor Advisory
http://secunia.com/advisories/20975 Vendor Advisory
http://secunia.com/advisories/20995 Vendor Advisory
http://secunia.com/advisories/21278 Vendor Advisory
http://secunia.com/advisories/22129 Vendor Advisory
http://secunia.com/advisories/23620 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200607-12.xml
http://securitytracker.com/id?1016414
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102490-1 Patch
http://www.debian.org/security/2006/dsa-1104
http://www.kb.cert.org/vuls/id/170113 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2006:118
http://www.novell.com/linux/security/advisories/2006_40_openoffice.html
http://www.openoffice.org/security/CVE-2006-2199.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2006-0573.html
http://www.securityfocus.com/archive/1/447035/100/0/threaded
http://www.securityfocus.com/bid/18738
http://www.ubuntu.com/usn/usn-313-1
http://www.ubuntu.com/usn/usn-313-2
http://www.vupen.com/english/advisories/2006/2607 Vendor Advisory
http://www.vupen.com/english/advisories/2006/2621 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/27564
https://issues.rpath.com/browse/RPL-475
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11082
http://fedoranews.org/cms/node/2343
http://secunia.com/advisories/20867 Vendor Advisory
http://secunia.com/advisories/20893 Vendor Advisory
http://secunia.com/advisories/20910 Vendor Advisory
http://secunia.com/advisories/20911 Vendor Advisory
http://secunia.com/advisories/20913 Vendor Advisory
http://secunia.com/advisories/20975 Vendor Advisory
http://secunia.com/advisories/20995 Vendor Advisory
http://secunia.com/advisories/21278 Vendor Advisory
http://secunia.com/advisories/22129 Vendor Advisory
http://secunia.com/advisories/23620 Vendor Advisory

Track CVE-2006-2198 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2000-0175Sun staroffice vulnerabilityBuffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.EPSS 2.4%9.3CVE-2007-4575Openoffice code injection vulnerabilityHSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via craft…EPSS 14%9.3CVE-2007-2834Apache openoffice integer overflow vulnerabilityInteger overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attack…EPSS 12%9.3CVE-2007-0245Openoffice memory buffer overflow vulnerabilityHeap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a crafted …EPSS 6.7%9.3CVE-2007-0238Openoffice memory buffer overflow vulnerabilityStack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5…EPSS 5.7%9.3CVE-2007-0239Openoffice vulnerabilityOpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in …EPSS 3.5%9.3CVE-2006-5870Openoffice vulnerabilityMultiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow use…EPSS 8.3%7.6CVE-2006-2199Openoffice vulnerabilityUnspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers …EPSS 3.5%

Source: NIST National Vulnerability Database (record CVE-2006-2198), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.