← Vulnerability feed

Vulnerability record · CVE-2006-3117 · published 30 June 2006

CVE-2006-3117: Openoffice memory buffer overflow vulnerability

Openoffice · Openoffice

Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."

7.6 CVSS 2.0 High EPSS 4.3% · top 9.2% CWE-119 · Memory buffer overflow
7.6CVSS 2.0 base score
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
58References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."

AV:N/AC:H/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://fedoranews.org/cms/node/2343
http://secunia.com/advisories/20867 Vendor Advisory
http://secunia.com/advisories/20893 Vendor Advisory
http://secunia.com/advisories/20910 Vendor Advisory
http://secunia.com/advisories/20911 Vendor Advisory
http://secunia.com/advisories/20913 Vendor Advisory
http://secunia.com/advisories/20975 Vendor Advisory
http://secunia.com/advisories/20995 Vendor Advisory
http://secunia.com/advisories/21278 Vendor Advisory
http://secunia.com/advisories/22129 Vendor Advisory
http://secunia.com/advisories/23620 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200607-12.xml
http://securitytracker.com/id?1016414
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102501-1 Patch
http://www.debian.org/security/2006/dsa-1104
http://www.mandriva.com/security/advisories?name=MDKSA-2006:118
http://www.ngssoftware.com/advisories/openoffice.txt Patch
http://www.novell.com/linux/security/advisories/2006_40_openoffice.html
http://www.openoffice.org/security/CVE-2006-3117.html Patch
http://www.redhat.com/support/errata/RHSA-2006-0573.html Vendor Advisory
http://www.securityfocus.com/archive/1/447035/100/0/threaded
http://www.securityfocus.com/bid/18739
http://www.ubuntu.com/usn/usn-313-1
http://www.ubuntu.com/usn/usn-313-2
http://www.vupen.com/english/advisories/2006/2607 Vendor Advisory
http://www.vupen.com/english/advisories/2006/2621 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/27571
https://issues.rpath.com/browse/RPL-475
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9704
http://fedoranews.org/cms/node/2343
http://secunia.com/advisories/20867 Vendor Advisory
http://secunia.com/advisories/20893 Vendor Advisory
http://secunia.com/advisories/20910 Vendor Advisory
http://secunia.com/advisories/20911 Vendor Advisory
http://secunia.com/advisories/20913 Vendor Advisory
http://secunia.com/advisories/20975 Vendor Advisory
http://secunia.com/advisories/20995 Vendor Advisory
http://secunia.com/advisories/21278 Vendor Advisory
http://secunia.com/advisories/22129 Vendor Advisory
http://secunia.com/advisories/23620 Vendor Advisory

Track CVE-2006-3117 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2000-0175Sun staroffice vulnerabilityBuffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.EPSS 2.4%9.3CVE-2007-4575Openoffice code injection vulnerabilityHSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via craft…EPSS 14%9.3CVE-2007-2834Apache openoffice integer overflow vulnerabilityInteger overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attack…EPSS 12%9.3CVE-2007-0245Openoffice memory buffer overflow vulnerabilityHeap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a crafted …EPSS 6.7%9.3CVE-2007-0238Openoffice memory buffer overflow vulnerabilityStack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5…EPSS 5.7%9.3CVE-2007-0239Openoffice vulnerabilityOpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in …EPSS 3.5%9.3CVE-2006-5870Openoffice vulnerabilityMultiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow use…EPSS 8.3%7.6CVE-2006-2198Openoffice permissions and access controls vulnerabilityOpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an Ope…EPSS 3.5%

Source: NIST National Vulnerability Database (record CVE-2006-3117), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.