VulnerabilityModified
CVE-2004-0752
OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow local users to read or list files of other users.
LOW 2.1EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow local users to read or list files of other users.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Affected
- openoffice/openoffice
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109483308421566&w=2
- http://secunia.com/advisories/12302/
- http://secunia.com/advisories/12546/
- http://secunia.com/advisories/12668/
- http://secunia.com/advisories/12914/
- http://secunia.com/advisories/12932/
- http://securitytracker.com/id?1011205Patch, Vendor Advisory
- http://www.openoffice.org/issues/show_bug.cgi?id=33357Exploit, Patch, Vendor Advisory
- http://www.osvdb.org/9804
- http://www.redhat.com/support/errata/RHSA-2004-446.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/11151
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17312
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10294
- http://marc.info/?l=bugtraq&m=109483308421566&w=2
- http://secunia.com/advisories/12302/
- http://secunia.com/advisories/12546/
- http://secunia.com/advisories/12668/
- http://secunia.com/advisories/12914/
- http://secunia.com/advisories/12932/
- http://securitytracker.com/id?1011205Patch, Vendor Advisory
- http://www.openoffice.org/issues/show_bug.cgi?id=33357Exploit, Patch, Vendor Advisory
- http://www.osvdb.org/9804
- http://www.redhat.com/support/errata/RHSA-2004-446.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/11151
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17312
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10294
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.