Apache / Openoffice
60 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-64407 | Apache OpenOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variables | MEDIUM | 5.3 | Nov 12, 2025 |
| CVE-2025-64406 | Apache OpenOffice: Possible memory corruption during CSV import | MEDIUM | 4.3 | Nov 12, 2025 |
| CVE-2025-64405 | Apache OpenOffice: Remote documents loaded without prompt via DDE function | HIGH | 7.5 | Nov 12, 2025 |
| CVE-2025-64404 | Apache OpenOffice: Remote documents loaded without prompt via background and bullet images | HIGH | 7.5 | Nov 12, 2025 |
| CVE-2025-64403 | Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc | HIGH | 8.1 | Nov 12, 2025 |
| CVE-2025-64402 | Apache OpenOffice: Remote documents loaded without prompt via OLE objects | MEDIUM | 6.5 | Nov 12, 2025 |
| CVE-2025-64401 | Apache OpenOffice: Remote documents loaded without prompt via IFrame | HIGH | 7.5 | Nov 12, 2025 |
| CVE-2023-47804 | Apache OpenOffice: Macro URL arbitrary script execution | HIGH | 8.8 | Dec 29, 2023 |
| CVE-2022-47502 | Apache OpenOffice: Macro URL arbitrary script execution | HIGH | 7.8 | Mar 24, 2023 |
| CVE-2022-38745 | Apache OpenOffice: Empty entry in Java class path | HIGH | 7.8 | Mar 24, 2023 |
| CVE-2022-37401 | Apache OpenOffice Weak Master Keys | HIGH | 8.8 | Aug 13, 2022 |
| CVE-2022-37400 | Apache OpenOffice Static Initialization Vector Allows to Recover Passwords for Web Connections Without Knowing the Master Password | HIGH | 8.8 | Aug 13, 2022 |
| CVE-2021-41832 | Content Manipulation with Certificate Validation Attack | HIGH | 7.5 | Oct 11, 2021 |
| CVE-2021-41831 | Timestamp Manipulation with Signature Wrapping | MEDIUM | 5.3 | Oct 11, 2021 |
| CVE-2021-41830 | Double Certificate Attack | HIGH | 7.5 | Oct 11, 2021 |
| CVE-2021-40439 | Billion Laughs | MEDIUM | 6.5 | Oct 7, 2021 |
| CVE-2021-28129 | DEB packaging for Apache OpenOffice 4.1.8 installed with a non-root userid and groupid | HIGH | 7.8 | Oct 7, 2021 |
| CVE-2021-33035 | Buffer overflow from a crafted DBF file | HIGH | 7.8 | Sep 23, 2021 |
| CVE-2021-30245 | Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks | HIGH | 8.8 | Apr 15, 2021 |
| CVE-2020-13958 | A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks pointing to an executable on the target u… | HIGH | 7.8 | Nov 17, 2020 |
| CVE-2012-5639 | OpenOffice: automatic opening of embedded external data | MEDIUM | 6.5 | Dec 20, 2019 |
| CVE-2011-2177 | OpenOffice.org: InteVyDis Demo of OpenOffice 0day. Released with VulnDisco 8.8 pack (release date May,2009) | HIGH | 7.8 | Nov 27, 2019 |
| CVE-2018-11790 | When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this… | HIGH | 7.8 | Jan 31, 2019 |
| CVE-2018-10583 | libreoffice: Information disclosure via SMB connection embedded in malicious file | HIGH | 7.5 | May 1, 2018 |
| CVE-2017-3157 | libreoffice: Arbitrary file disclosure in Calc and Writer | MEDIUM | 5.5 | Nov 20, 2017 |
Showing 1 to 25 of 60 CVEs