OpenOffice.org 2.0 and earlier, when hyperlinks has been disabled, does not prevent the user from clicking the WWW-browser button in the Hyperlink dialog, which makes it easier for attackers to trick the user into bypassing intended security settings.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-4631
http://www.mandriva.com/security/advisories?name=MDKSA-2006:033