Vulnerability Name: | CVE-2005-4636 (CCN-23903) | ||||||||
Assigned: | 2005-12-28 | ||||||||
Published: | 2005-12-28 | ||||||||
Updated: | 2009-11-12 | ||||||||
Summary: | OpenOffice.org 2.0 and earlier, when hyperlinks has been disabled, does not prevent the user from clicking the WWW-browser button in the Hyperlink dialog, which makes it easier for attackers to trick the user into bypassing intended security settings. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-4636 Source: CCN Type: OpenOffice Issue list Issue 53491 Source: CONFIRM Type: UNKNOWN http://qa.openoffice.org/issues/show_bug.cgi?id=53491 Source: CCN Type: SECTRACK ID: 1015419 OpenOffice WWW-Browser Button May Not Properly Enforce Hyperlink Security Restrictions Source: SECTRACK Type: Patch 1015419 Source: MANDRIVA Type: UNKNOWN MDKSA-2006:033 Source: CCN Type: OpenOffice.org Web site OpenOffice.org Source: CCN Type: OSVDB ID: 22074 OpenOffice.org (OOo) Hyperlink Execution Setting Bypass Source: XF Type: UNKNOWN openoffice-browser-security-bypass(23903) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |