CVE-2025-64403

Severity
8.1HIGH
EPSS
0.0%
top 98.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12

Description

Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause such links to be loaded without prompt. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version 4.1.16, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc2025-11-12
GHSA
GHSA-3r8r-ch94-c42m: Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources"2025-11-12
CVE-2025-64403 (HIGH CVSS 8.1) | Apache OpenOffice Calc spreadsheet | cvebase.io