← Vulnerability feed

Vulnerability record · CVE-2007-0238 · published 21 March 2007

CVE-2007-0238: Openoffice memory buffer overflow vulnerability

Openoffice · Openoffice

Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5 Patch, allows user-assisted remote attackers to execute arbitrary code via a document with a long Note.

9.3 CVSS 2.0 High EPSS 5.7% · top 7.2% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
5.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
56References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5 Patch, allows user-assisted remote attackers to execute arbitrary code via a document with a long Note.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html
http://secunia.com/advisories/24465 Vendor Advisory
http://secunia.com/advisories/24550 Vendor Advisory
http://secunia.com/advisories/24588 Vendor Advisory
http://secunia.com/advisories/24613 Vendor Advisory
http://secunia.com/advisories/24646 Vendor Advisory
http://secunia.com/advisories/24647 Vendor Advisory
http://secunia.com/advisories/24676 Vendor Advisory
http://secunia.com/advisories/24810 Vendor Advisory
http://secunia.com/advisories/24906 Vendor Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102794-1
http://www.debian.org/security/2007/dsa-1270 Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:073
http://www.ngssoftware.com/advisories/high-risk-vulnerabilities-in-the-openoffice-suite/
http://www.openoffice.org/security/CVE-2007-0238
http://www.redhat.com/support/errata/RHSA-2007-0033.html
http://www.redhat.com/support/errata/RHSA-2007-0069.html
http://www.securityfocus.com/archive/1/464724/100/0/threaded
http://www.securityfocus.com/bid/23067
http://www.securitytracker.com/id?1017799
http://www.ubuntu.com/usn/usn-444-1
http://www.vupen.com/english/advisories/2007/1032 Vendor Advisory
http://www.vupen.com/english/advisories/2007/1117 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/33112
https://issues.foresightlinux.org/browse/FL-211
https://issues.rpath.com/browse/RPL-1118
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8968
http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html
http://secunia.com/advisories/24465 Vendor Advisory
http://secunia.com/advisories/24550 Vendor Advisory
http://secunia.com/advisories/24588 Vendor Advisory
http://secunia.com/advisories/24613 Vendor Advisory
http://secunia.com/advisories/24646 Vendor Advisory
http://secunia.com/advisories/24647 Vendor Advisory
http://secunia.com/advisories/24676 Vendor Advisory
http://secunia.com/advisories/24810 Vendor Advisory
http://secunia.com/advisories/24906 Vendor Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102794-1
http://www.debian.org/security/2007/dsa-1270 Vendor Advisory

Track CVE-2007-0238 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2007-4575Openoffice code injection vulnerabilityHSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via craft…EPSS 14%9.3CVE-2007-0245Openoffice memory buffer overflow vulnerabilityHeap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a crafted …EPSS 6.7%9.3CVE-2007-0239Openoffice vulnerabilityOpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in …EPSS 3.5%9.3CVE-2006-5870Openoffice vulnerabilityMultiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow use…EPSS 8.3%7.6CVE-2006-2198Openoffice permissions and access controls vulnerabilityOpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an Ope…EPSS 3.5%7.6CVE-2006-2199Openoffice vulnerabilityUnspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers …EPSS 3.5%7.6CVE-2006-3117Openoffice memory buffer overflow vulnerabilityHeap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbi…EPSS 4.3%6.8CVE-2007-5745Openoffice memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly execute ar…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2007-0238), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.