Apache / Apache Openoffice
27 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59265 | Apache OpenOffice, Apache OpenOffice: Opening a malicious document can lead to system takeover | n/a | Oct 2, 2026 | |
| CVE-2025-64407 | Apache OpenOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variables | MEDIUM | 5.3 | Nov 12, 2025 |
| CVE-2025-64406 | Apache OpenOffice: Possible memory corruption during CSV import | MEDIUM | 4.3 | Nov 12, 2025 |
| CVE-2025-64405 | Apache OpenOffice: Remote documents loaded without prompt via DDE function | HIGH | 7.5 | Nov 12, 2025 |
| CVE-2025-64404 | Apache OpenOffice: Remote documents loaded without prompt via background and bullet images | HIGH | 7.5 | Nov 12, 2025 |
| CVE-2025-64403 | Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc | HIGH | 8.1 | Nov 12, 2025 |
| CVE-2025-64402 | Apache OpenOffice: Remote documents loaded without prompt via OLE objects | MEDIUM | 6.5 | Nov 12, 2025 |
| CVE-2025-64401 | Apache OpenOffice: Remote documents loaded without prompt via IFrame | HIGH | 7.5 | Nov 12, 2025 |
| CVE-2023-47804 | Apache OpenOffice: Macro URL arbitrary script execution | HIGH | 8.8 | Dec 29, 2023 |
| CVE-2022-47502 | Apache OpenOffice: Macro URL arbitrary script execution | HIGH | 7.8 | Mar 24, 2023 |
| CVE-2022-38745 | Apache OpenOffice: Empty entry in Java class path | HIGH | 7.8 | Mar 24, 2023 |
| CVE-2022-37401 | Apache OpenOffice Weak Master Keys | HIGH | 8.8 | Aug 13, 2022 |
| CVE-2022-37400 | Apache OpenOffice Static Initialization Vector Allows to Recover Passwords for Web Connections Without Knowing the Master Password | HIGH | 8.8 | Aug 13, 2022 |
| CVE-2021-41832 | Content Manipulation with Certificate Validation Attack | HIGH | 7.5 | Oct 11, 2021 |
| CVE-2021-41831 | Timestamp Manipulation with Signature Wrapping | MEDIUM | 5.3 | Oct 11, 2021 |
| CVE-2021-41830 | Double Certificate Attack | HIGH | 7.5 | Oct 11, 2021 |
| CVE-2021-40439 | Billion Laughs | MEDIUM | 6.5 | Oct 7, 2021 |
| CVE-2021-28129 | DEB packaging for Apache OpenOffice 4.1.8 installed with a non-root userid and groupid | HIGH | 7.8 | Oct 7, 2021 |
| CVE-2021-33035 | Buffer overflow from a crafted DBF file | HIGH | 7.8 | Sep 23, 2021 |
| CVE-2021-30245 | Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks | HIGH | 8.8 | Apr 15, 2021 |
| CVE-2018-11790 | When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this… | HIGH | 7.8 | Jan 31, 2019 |
| CVE-2017-3157 | libreoffice: Arbitrary file disclosure in Calc and Writer | MEDIUM | 5.5 | Nov 20, 2017 |
| CVE-2017-12608 | libreoffice: Out-of-bounds write in the WW8RStyle::ImportOldFormatStyles functionality | HIGH | 7.8 | Nov 20, 2017 |
| CVE-2017-12607 | libreoffice: Out-of-bounds write in the PPTStyleSheet::PPTStyleSheet functionality | HIGH | 7.8 | Nov 20, 2017 |
| CVE-2017-9806 | libreoffice: Out-of-bounds write in the WW8Fonts::WW8Fonts functionality | HIGH | 7.8 | Nov 20, 2017 |
Showing 1 to 25 of 27 CVEs