Unrated severityNVD Advisory· Published Aug 25, 2010· Updated Apr 29, 2026
CVE-2010-2935
CVE-2010-2935
Description
simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an "integer truncation error."
Affected products
1- cpe:2.3:a:openoffice:openoffice.org:3.2.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
30- secunia.com/advisories/40775nvdVendor Advisory
- secunia.com/advisories/41052nvdVendor Advisory
- www.vupen.com/english/advisories/2010/2003nvdVendor Advisory
- www.vupen.com/english/advisories/2010/2149nvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlnvd
- secunia.com/advisories/41235nvd
- secunia.com/advisories/42927nvd
- secunia.com/advisories/43105nvd
- secunia.com/advisories/60799nvd
- securityevaluators.com/files/papers/CrashAnalysis.pdfnvd
- ubuntu.com/usn/usn-1056-1nvd
- www.debian.org/security/2010/dsa-2099nvd
- www.gentoo.org/security/en/glsa/glsa-201408-19.xmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.openoffice.org/security/cves/CVE-2010-2935_CVE-2010-2936.htmlnvd
- www.openoffice.org/servlets/ReadMsgnvd
- www.openwall.com/lists/oss-security/2010/08/11/1nvd
- www.openwall.com/lists/oss-security/2010/08/11/4nvd
- www.oracle.com/technetwork/topics/security/cpujan2011-194091.htmlnvd
- www.redhat.com/support/errata/RHSA-2010-0643.htmlnvd
- www.securitytracker.com/idnvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2010/2228nvd
- www.vupen.com/english/advisories/2010/2905nvd
- www.vupen.com/english/advisories/2011/0150nvd
- www.vupen.com/english/advisories/2011/0230nvd
- www.vupen.com/english/advisories/2011/0279nvd
- bugzilla.redhat.com/show_bug.cginvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12063nvd
News mentions
0No linked articles in our index yet.