CVE-2006-2199
Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to escape the Java sandbox and conduct unauthorized activities via certain applets in OpenOffice…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to escape the Java sandbox and conduct unauthorized activities via certain applets in OpenOffice documents.
- CVSS 2.0
- 7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 3.47% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- openoffice/openoffice · sun/staroffice
- Source
- security@debian.org
References
- http://fedoranews.org/cms/node/2343
- http://secunia.com/advisories/20867Vendor Advisory
- http://secunia.com/advisories/20893Vendor Advisory
- http://secunia.com/advisories/20910Vendor Advisory
- http://secunia.com/advisories/20911Vendor Advisory
- http://secunia.com/advisories/20913Vendor Advisory
- http://secunia.com/advisories/20975Vendor Advisory
- http://secunia.com/advisories/20995Vendor Advisory
- http://secunia.com/advisories/21278Vendor Advisory
- http://secunia.com/advisories/23620Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200607-12.xml
- http://securitytracker.com/id?1016414
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102475-1
- http://www.debian.org/security/2006/dsa-1104
- http://www.kb.cert.org/vuls/id/243681US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:118
- http://www.novell.com/linux/security/advisories/2006_40_openoffice.html
- http://www.openoffice.org/security/CVE-2006-2199.html
- http://www.redhat.com/support/errata/RHSA-2006-0573.html
- http://www.securityfocus.com/archive/1/447035/100/0/threaded
- http://www.securityfocus.com/bid/18737
- http://www.ubuntu.com/usn/usn-313-1
- http://www.ubuntu.com/usn/usn-313-2
- http://www.vupen.com/english/advisories/2006/2607Vendor Advisory
- http://www.vupen.com/english/advisories/2006/2621Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27569
- https://issues.rpath.com/browse/RPL-475
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11338
- http://fedoranews.org/cms/node/2343
- http://secunia.com/advisories/20867Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.