← Vulnerability feed

Vulnerability record · CVE-2010-4643 · published 28 January 2011

CVE-2010-4643: Apache openoffice out-of-bounds write vulnerability

Apache · Openoffice

Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.

9.3 CVSS 2.0 High EPSS 10% · top 4.5% CWE-787 · Out-of-bounds write
9.3CVSS 2.0 base score
10%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
44References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://osvdb.org/70718 Broken Link
http://secunia.com/advisories/40775 Broken Link
http://secunia.com/advisories/42999 Broken Link
http://secunia.com/advisories/43065 Broken Link
http://secunia.com/advisories/43105 Broken Link
http://secunia.com/advisories/43118 Broken Link
http://secunia.com/advisories/60799 Broken Link
http://ubuntu.com/usn/usn-1056-1 Third Party Advisory
http://www.debian.org/security/2011/dsa-2151 Third Party Advisory
http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2011:027 Broken Link
http://www.openoffice.org/security/cves/CVE-2010-4643.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2011-0181.html Broken Link
http://www.redhat.com/support/errata/RHSA-2011-0182.html Broken Link
http://www.securityfocus.com/bid/46031 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1025002 Broken LinkThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2011/0230 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2011/0232 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2011/0279 Broken LinkVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=667588 Issue TrackingThird Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/65441 Third Party AdvisoryVDB Entry
http://osvdb.org/70718 Broken Link
http://secunia.com/advisories/40775 Broken Link
http://secunia.com/advisories/42999 Broken Link
http://secunia.com/advisories/43065 Broken Link
http://secunia.com/advisories/43105 Broken Link
http://secunia.com/advisories/43118 Broken Link
http://secunia.com/advisories/60799 Broken Link
http://ubuntu.com/usn/usn-1056-1 Third Party Advisory
http://www.debian.org/security/2011/dsa-2151 Third Party Advisory
http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2011:027 Broken Link
http://www.openoffice.org/security/cves/CVE-2010-4643.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2011-0181.html Broken Link
http://www.redhat.com/support/errata/RHSA-2011-0182.html Broken Link
http://www.securityfocus.com/bid/46031 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1025002 Broken LinkThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2011/0230 Broken LinkVendor Advisory

Track CVE-2010-4643 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2014-3524Apache openoffice command injection vulnerabilityApache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc sp…EPSS 15%9.3CVE-2010-3450Apache openoffice path traversal vulnerabilityMultiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a…EPSS 11%9.3CVE-2010-3451Apache openoffice use after free vulnerabilityUse-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica…EPSS 10%9.3CVE-2010-3452Apache openoffice use after free vulnerabilityUse-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica…EPSS 10%9.3CVE-2010-3453Apache openoffice out-of-bounds write vulnerabilityThe WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number…EPSS 9.7%9.3CVE-2010-3454Apache openoffice vulnerabilityMultiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote atta…EPSS 10%9.3CVE-2010-4253Apache openoffice out-of-bounds write vulnerabilityHeap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applicatio…EPSS 10%9.3CVE-2010-0395Canonical ubuntu linux vulnerabilityOpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Pyth…EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2010-4643), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.