← Vulnerability feed

Vulnerability record · CVE-2007-5745 · published 17 April 2008

CVE-2007-5745: Openoffice memory buffer overflow vulnerability

Openoffice · Openoffice

Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted (1) Attribute and (2) Font Description records.

6.8 CVSS 2.0 Medium EPSS 4.1% · top 9.6% CWE-119 · Memory buffer overflow
6.8CVSS 2.0 base score
4.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
54References
16 Jun 2026Last modified by NVD

Description

Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted (1) Attribute and (2) Font Description records.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=691
http://secunia.com/advisories/29852 Vendor Advisory
http://secunia.com/advisories/29864 PatchVendor Advisory
http://secunia.com/advisories/29871 Vendor Advisory
http://secunia.com/advisories/29910 Vendor Advisory
http://secunia.com/advisories/29913 Vendor Advisory
http://secunia.com/advisories/29987 Vendor Advisory
http://secunia.com/advisories/30100 Vendor Advisory
http://secunia.com/advisories/30179 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200805-16.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-26-231601-1
http://www.debian.org/security/2008/dsa-1547 Patch
http://www.mandriva.com/security/advisories?name=MDVSA-2008:095
http://www.novell.com/linux/security/advisories/2008_23_openoffice.html
http://www.openoffice.org/security/bulletin.html Patch
http://www.openoffice.org/security/cves/CVE-2007-4770.html
http://www.openoffice.org/security/cves/CVE-2007-5745.html Patch
http://www.redhat.com/support/errata/RHSA-2008-0175.html
http://www.securityfocus.com/bid/28819
http://www.securitytracker.com/id?1019891
http://www.ubuntu.com/usn/usn-609-1
http://www.vupen.com/english/advisories/2008/1253/references Vendor Advisory
http://www.vupen.com/english/advisories/2008/1375/references Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=435678
https://exchange.xforce.ibmcloud.com/vulnerabilities/41863
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11006
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=691
http://secunia.com/advisories/29852 Vendor Advisory
http://secunia.com/advisories/29864 PatchVendor Advisory
http://secunia.com/advisories/29871 Vendor Advisory
http://secunia.com/advisories/29910 Vendor Advisory
http://secunia.com/advisories/29913 Vendor Advisory
http://secunia.com/advisories/29987 Vendor Advisory
http://secunia.com/advisories/30100 Vendor Advisory
http://secunia.com/advisories/30179 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200805-16.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-26-231601-1
http://www.debian.org/security/2008/dsa-1547 Patch
http://www.mandriva.com/security/advisories?name=MDVSA-2008:095

Track CVE-2007-5745 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2007-4575Openoffice code injection vulnerabilityHSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via craft…EPSS 14%9.3CVE-2007-0245Openoffice memory buffer overflow vulnerabilityHeap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a crafted …EPSS 6.7%9.3CVE-2007-0238Openoffice memory buffer overflow vulnerabilityStack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5…EPSS 5.7%9.3CVE-2007-0239Openoffice vulnerabilityOpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in …EPSS 3.5%9.3CVE-2006-5870Openoffice vulnerabilityMultiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow use…EPSS 8.3%7.6CVE-2006-2198Openoffice permissions and access controls vulnerabilityOpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an Ope…EPSS 3.5%7.6CVE-2006-2199Openoffice vulnerabilityUnspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers …EPSS 3.5%7.6CVE-2006-3117Openoffice memory buffer overflow vulnerabilityHeap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbi…EPSS 4.3%

Source: NIST National Vulnerability Database (record CVE-2007-5745), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.