← Back

CVE-2017-9806

nvd nist
Published: Nov 20, 2017Modified: May 13, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.

Affected (1)

Products: Apache: Openoffice
1 product
Openoffice
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.1.4

References (4)

Source: security@apache.org
Vendor Advisory
Source: security@apache.org
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry

Timeline

No history available yet.