← Vulnerability feed

Vulnerability record · CVE-2008-2152 · published 10 June 2008

CVE-2008-2152: Openoffice.org vulnerability

Openoffice · Openoffice.Org

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.

9.3 CVSS 2.0 High EPSS 5.7% · top 7.2% CWE-189 · CWE-189
9.3CVSS 2.0 base score
5.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
44References
16 Jun 2026Last modified by NVD

Description

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=714
http://secunia.com/advisories/30599 Vendor Advisory
http://secunia.com/advisories/30633
http://secunia.com/advisories/30634
http://secunia.com/advisories/30635
http://secunia.com/advisories/31029
http://security.gentoo.org/glsa/glsa-200807-05.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-26-237944-1
http://www.mandriva.com/security/advisories?name=MDVSA-2008:137
http://www.mandriva.com/security/advisories?name=MDVSA-2008:138
http://www.openoffice.org/security/cves/CVE-2008-2152.html
http://www.redhat.com/support/errata/RHSA-2008-0537.html
http://www.redhat.com/support/errata/RHSA-2008-0538.html
http://www.securityfocus.com/bid/29622
http://www.securitytracker.com/id?1020219
http://www.vupen.com/english/advisories/2008/1773
http://www.vupen.com/english/advisories/2008/1804/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/42957
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9787
https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00385.html
https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00473.html
https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00499.html
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=714
http://secunia.com/advisories/30599 Vendor Advisory
http://secunia.com/advisories/30633
http://secunia.com/advisories/30634
http://secunia.com/advisories/30635
http://secunia.com/advisories/31029
http://security.gentoo.org/glsa/glsa-200807-05.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-26-237944-1
http://www.mandriva.com/security/advisories?name=MDVSA-2008:137
http://www.mandriva.com/security/advisories?name=MDVSA-2008:138
http://www.openoffice.org/security/cves/CVE-2008-2152.html
http://www.redhat.com/support/errata/RHSA-2008-0537.html
http://www.redhat.com/support/errata/RHSA-2008-0538.html
http://www.securityfocus.com/bid/29622
http://www.securitytracker.com/id?1020219
http://www.vupen.com/english/advisories/2008/1773
http://www.vupen.com/english/advisories/2008/1804/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/42957

Track CVE-2008-2152 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-3570Openoffice.org vulnerabilityUnspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco …EPSS 1.5%9.3CVE-2010-2935Openoffice.org vulnerabilitysimpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary …EPSS 7.1%9.3CVE-2010-2936Openoffice.org vulnerabilityInteger overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of se…EPSS 7.1%9.3CVE-2009-3571Openoffice.org memory buffer overflow vulnerabilityUnspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco …EPSS 1.3%9.3CVE-2009-0200Openoffice.org vulnerabilityInteger underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code vi…EPSS 6.7%9.3CVE-2009-0201Openoffice.org memory buffer overflow vulnerabilityHeap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrar…EPSS 6.7%9.3CVE-2009-0259Openoffice.org vulnerabilityThe Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary …EPSS 7.5%9.3CVE-2008-2237Openoffice.org memory buffer overflow vulnerabilityHeap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associat…EPSS 6.1%

Source: NIST National Vulnerability Database (record CVE-2008-2152), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.