Apache Software Foundation Apache Openoffice vulnerabilities
25 known vulnerabilities affecting apache_software_foundation/apache_openoffice.
Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH18MEDIUM7
Vulnerabilities
Page 2 of 2
CVE-2017-9806P4HIGHCVSS 7.8v4.0.0 to 4.1.3, and some previous releases, including some using our old OpenOffice.org brand2017-11-20
CVE-2017-9806 [HIGH] CWE-787 CVE-2017-9806: A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fo
A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.
nvd
CVE-2023-2255P4MEDIUMCVSS 5.3≤ 4.1.152023-05-25
CVE-2023-2255 [MEDIUM] CWE-264 CVE-2023-2255: Improper access control in editor components of The Document Foundation LibreOffice allowed an attac
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the us
nvd
CVE-2017-3157P4MEDIUMCVSS 5.5v4.0.0 to 4.1.3, and some previous releases, including some using our old OpenOffice.org brand2017-11-20
CVE-2017-3157 [MEDIUM] CWE-200 CVE-2017-3157: By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could cra
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send t
nvd
CVE-2021-25635P4MEDIUMCVSS 5.5≥ Apache OpenOffice, ≤ 4.1.10≥ OpenOffice.org, ≤ 3.42025-03-21
CVE-2021-25635 [MEDIUM] CWE-295 CVE-2021-25635: An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an
An Improper Certificate Validation vulnerability in LibreOffice allowed
an attacker to self sign an ODF document, with a signature untrusted by
the target, then modify it to change the signature algorithm to an
invalid (or unknown to LibreOffice) algorithm and LibreOffice would incorrectly present such a signature with an unknown algorithm as a
valid
nvd
CVE-2025-64406P4MEDIUMCVSS 4.3≤ 4.1.152025-11-12
CVE-2025-64406 [MEDIUM] CWE-787 CVE-2025-64406: An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a documen
An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a document that would crash the program, or otherwise corrupt other memory areas.
This issue affects Apache OpenOffice: through 4.1.15.
Users are recommended to upgrade to version 4.1.16, which fixes the issue.
nvd
← Previous2 / 2