← Vulnerability feed

Vulnerability record · CVE-2010-2935 · published 25 August 2010

CVE-2010-2935: Openoffice.org vulnerability

Openoffice · Openoffice.Org

simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an "integer truncation error."

9.3 CVSS 2.0 High EPSS 7.1% · top 6.0% CWE-189 · CWE-189
9.3CVSS 2.0 base score
7.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
60References
16 Jun 2026Last modified by NVD

Description

simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an "integer truncation error."

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html
http://secunia.com/advisories/40775 Vendor Advisory
http://secunia.com/advisories/41052 Vendor Advisory
http://secunia.com/advisories/41235
http://secunia.com/advisories/42927
http://secunia.com/advisories/43105
http://secunia.com/advisories/60799
http://securityevaluators.com/files/papers/CrashAnalysis.pdf
http://ubuntu.com/usn/usn-1056-1
http://www.debian.org/security/2010/dsa-2099
http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2010:221
http://www.openoffice.org/security/cves/CVE-2010-2935_CVE-2010-2936.html
http://www.openoffice.org/servlets/ReadMsg?list=dev&msgNo=27690
http://www.openwall.com/lists/oss-security/2010/08/11/1
http://www.openwall.com/lists/oss-security/2010/08/11/4
http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html
http://www.redhat.com/support/errata/RHSA-2010-0643.html
http://www.securitytracker.com/id?1024352
http://www.securitytracker.com/id?1024976
http://www.vupen.com/english/advisories/2010/2003 Vendor Advisory
http://www.vupen.com/english/advisories/2010/2149 Vendor Advisory
http://www.vupen.com/english/advisories/2010/2228
http://www.vupen.com/english/advisories/2010/2905
http://www.vupen.com/english/advisories/2011/0150
http://www.vupen.com/english/advisories/2011/0230
http://www.vupen.com/english/advisories/2011/0279
https://bugzilla.redhat.com/show_bug.cgi?id=622529
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12063
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html
http://secunia.com/advisories/40775 Vendor Advisory
http://secunia.com/advisories/41052 Vendor Advisory
http://secunia.com/advisories/41235
http://secunia.com/advisories/42927
http://secunia.com/advisories/43105
http://secunia.com/advisories/60799
http://securityevaluators.com/files/papers/CrashAnalysis.pdf
http://ubuntu.com/usn/usn-1056-1

Track CVE-2010-2935 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-3570Openoffice.org vulnerabilityUnspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco …EPSS 1.5%9.3CVE-2010-2936Openoffice.org vulnerabilityInteger overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of se…EPSS 7.1%9.3CVE-2009-3571Openoffice.org memory buffer overflow vulnerabilityUnspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco …EPSS 1.3%9.3CVE-2009-0200Openoffice.org vulnerabilityInteger underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code vi…EPSS 6.7%9.3CVE-2009-0201Openoffice.org memory buffer overflow vulnerabilityHeap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrar…EPSS 6.7%9.3CVE-2009-0259Openoffice.org vulnerabilityThe Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary …EPSS 7.5%9.3CVE-2008-2237Openoffice.org memory buffer overflow vulnerabilityHeap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associat…EPSS 6.1%9.3CVE-2008-2238Openoffice.org memory buffer overflow vulnerabilityMultiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EM…EPSS 6.7%

Source: NIST National Vulnerability Database (record CVE-2010-2935), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.