9.3
CRITICAL
CVE-2014-3524
Apache OpenOffice Command Injection Vulnerability
Description

Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.

INFO

Published Date :

Aug. 26, 2014, 2:55 p.m.

Last Modified :

Feb. 7, 2022, 4:25 p.m.

Remotely Exploitable :

Yes !

Impact Score :

10.0

Exploitability Score :

8.6
Public PoC/Exploit Available at Github

CVE-2014-3524 has a 3 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2014-3524 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Libreoffice libreoffice
1 Apache openoffice
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2014-3524.

URL Resource
http://blog.documentfoundation.org/2014/08/28/libreoffice-4-3-1-fresh-announced/ Vendor Advisory
http://secunia.com/advisories/59600 Broken Link
http://secunia.com/advisories/59877 Broken Link
http://secunia.com/advisories/60235 Broken Link
http://www.openoffice.org/security/cves/CVE-2014-3524.html Vendor Advisory
http://www.securityfocus.com/archive/1/533200/100/0/threaded Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/69351 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1030755 Broken Link Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/95421 Third Party Advisory VDB Entry
https://security.gentoo.org/glsa/201603-05 Third Party Advisory

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

1.Explain the DOM XSS vulnerability.

Updated: 4 months, 3 weeks ago
0 stars 0 fork 0 watcher
Born at : Feb. 10, 2024, 6:12 a.m. This repo has been linked 1 different CVEs too.

None

C#

Updated: 1 year, 3 months ago
0 stars 0 fork 0 watcher
Born at : June 3, 2023, 3:41 p.m. This repo has been linked 1 different CVEs too.

CSV injection Sanitizer written in Go

Go

Updated: 3 years, 1 month ago
3 stars 1 fork 1 watcher
Born at : March 12, 2018, 6:19 p.m. This repo has been linked 1 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2014-3524 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2014-3524 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • Modified Analysis by [email protected]

    Feb. 07, 2022

    Action Type Old Value New Value
    Removed Evaluator Description <a href="http://cwe.mitre.org/data/definitions/77.html" target="_blank">CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')</a>
    Changed Reference Type http://blog.documentfoundation.org/2014/08/28/libreoffice-4-3-1-fresh-announced/ No Types Assigned http://blog.documentfoundation.org/2014/08/28/libreoffice-4-3-1-fresh-announced/ Vendor Advisory
    Changed Reference Type http://secunia.com/advisories/59600 No Types Assigned http://secunia.com/advisories/59600 Broken Link
    Changed Reference Type http://secunia.com/advisories/59877 No Types Assigned http://secunia.com/advisories/59877 Broken Link
    Changed Reference Type http://secunia.com/advisories/60235 No Types Assigned http://secunia.com/advisories/60235 Broken Link
    Changed Reference Type http://www.openoffice.org/security/cves/CVE-2014-3524.html No Types Assigned http://www.openoffice.org/security/cves/CVE-2014-3524.html Vendor Advisory
    Changed Reference Type http://www.securityfocus.com/archive/1/533200/100/0/threaded No Types Assigned http://www.securityfocus.com/archive/1/533200/100/0/threaded Broken Link, Third Party Advisory, VDB Entry
    Changed Reference Type http://www.securityfocus.com/bid/69351 No Types Assigned http://www.securityfocus.com/bid/69351 Broken Link, Third Party Advisory, VDB Entry
    Changed Reference Type http://www.securitytracker.com/id/1030755 No Types Assigned http://www.securitytracker.com/id/1030755 Broken Link, Third Party Advisory, VDB Entry
    Changed Reference Type https://exchange.xforce.ibmcloud.com/vulnerabilities/95421 No Types Assigned https://exchange.xforce.ibmcloud.com/vulnerabilities/95421 Third Party Advisory, VDB Entry
    Changed Reference Type https://security.gentoo.org/glsa/201603-05 No Types Assigned https://security.gentoo.org/glsa/201603-05 Third Party Advisory
    Removed CWE NIST NVD-CWE-Other
    Added CWE NIST CWE-77
    Changed CPE Configuration OR *cpe:2.3:a:apache:openoffice:4.0.0:*:*:*:*:*:*:* *cpe:2.3:a:apache:openoffice:4.0.1:*:*:*:*:*:*:* *cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:* versions up to (including) 4.1.0 OR *cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* versions up to (excluding) 4.2.6 *cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* versions from (including) 4.3.0 up to (excluding) 4.3.1
    Added CPE Configuration OR *cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:* versions up to (excluding) 4.1.1
  • CVE Modified by [email protected]

    Oct. 09, 2018

    Action Type Old Value New Value
    Removed Reference http://www.securityfocus.com/archive/1/archive/1/533200/100/0/threaded [No Types Assigned]
    Added Reference http://www.securityfocus.com/archive/1/533200/100/0/threaded [No Types Assigned]
  • CVE Modified by [email protected]

    Aug. 29, 2017

    Action Type Old Value New Value
    Removed Reference http://xforce.iss.net/xforce/xfdb/95421 [No Types Assigned]
    Added Reference https://exchange.xforce.ibmcloud.com/vulnerabilities/95421 [No Types Assigned]
  • CVE Modified by [email protected]

    Jan. 07, 2017

    Action Type Old Value New Value
    Added Reference http://www.openoffice.org/security/cves/CVE-2014-3524.html [No Types Assigned]
    Added Reference http://secunia.com/advisories/60235 [No Types Assigned]
    Added Reference http://secunia.com/advisories/59877 [No Types Assigned]
    Added Reference http://secunia.com/advisories/59600 [No Types Assigned]
    Added Reference http://blog.documentfoundation.org/2014/08/28/libreoffice-4-3-1-fresh-announced/ [No Types Assigned]
  • CVE Modified by [email protected]

    Dec. 03, 2016

    Action Type Old Value New Value
    Added Reference https://security.gentoo.org/glsa/201603-05 [No Types Assigned]
  • Initial Analysis by [email protected]

    Aug. 27, 2014

    Action Type Old Value New Value
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2014-3524 is associated with the following CWEs:

Exploit Prediction

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.

0.60 }} -0.23%

score

0.78118

percentile

CVSS2 - Vulnerability Scoring System
Access Vector
Access Complexity
Authentication
Confidentiality
Integrity
Availability