← Back

Openoffice

openoffice

Vendor: Apache • 60 CVEs

CVEs (60)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Apache
DebianLibreoffice
3Debian Linux
LibreofficeOpenoffice
Nov 21, 2024
Dec 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
LibreOffice and OpenOffice automatically open embedded content
1Apache
1Openoffice
Nov 21, 2024
Nov 27, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.
2Apache
Canonical
2Openoffice
Ubuntu Linux
Nov 21, 2024
Jan 31, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string...Show more
When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string length calculation.Show less
5Apache
CanonicalDebian+2 more
7Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
Nov 21, 2024
May 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=fi...Show more
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.Show less
3Apache
DebianRedhat
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+5 more
May 13, 2026
Nov 20, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker b...Show more
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send the document back to the attacker. The vulnerability is mitigated by the need for the attacker to know the precise file path in the target system, and the need to trick the user into saving the document and sending it back.Show less
2Apache
Debian
2Debian Linux
Openoffice
May 13, 2026
Nov 20, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and appli...Show more
A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.Show less
2Apache
Debian
2Debian Linux
Openoffice
May 13, 2026
Nov 20, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potent...Show more
A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.Show less
1Apache
1Openoffice
May 13, 2026
Nov 20, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malicious documents that cause denial of service (memory corruption and appli...Show more
A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.Show less
1Apache
1Openoffice
May 13, 2026
Nov 20, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that allows execution of arbitrary code with elevated privileges. This requir...Show more
The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that allows execution of arbitrary code with elevated privileges. This requires that the location in which the installer is run has been previously poisoned by a file that impersonates a dynamic-link library that the installer depends upon.Show less
1Apache
1Openoffice
May 13, 2026
Nov 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for Windows. The PC must have previously been infected by a Trojan Horse application (or...Show more
An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for Windows. The PC must have previously been infected by a Trojan Horse application (or user) running with administrative privilege. Any installer with the unquoted search path vulnerability becomes a delayed trigger for the exploit.Show less
1Apache
1Openoffice
May 6, 2026
Aug 5, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute arbitrary code via crafted MetaActions in an (1) ODP or (2) OTP file.
4Apache
CanonicalDebian+1 more
4Debian Linux
LibreofficeOpenoffice+1 more
May 6, 2026
Nov 10, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via an index to a...Show more
LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via an index to a non-existent bookmark in a DOC file.Show less
4Apache
CanonicalDebian+1 more
4Debian Linux
LibreofficeOpenoffice+1 more
May 6, 2026
Nov 10, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long...Show more
Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.Show less
4Apache
CanonicalDebian+1 more
4Debian Linux
LibreofficeOpenoffice+1 more
May 6, 2026
Nov 10, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service...Show more
Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via crafted PrinterSetup data in an ODF document.Show less
4Apache
CanonicalDebian+1 more
4Debian Linux
LibreofficeOpenoffice+1 more
May 6, 2026
Nov 10, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to o...Show more
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.Show less
6Apache
CanonicalDebian+3 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+5 more
May 6, 2026
Apr 28, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP docum...Show more
The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.Show less
3Apache
LibreofficeRedhat
5Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+2 more
May 6, 2026
Aug 27, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects.
2Apache
Libreoffice
2Libreoffice
Openoffice
May 6, 2026
Aug 26, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.
1Apache
1Openoffice
Apr 29, 2026
Jul 31, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted element in an OOXML document file.
1Apache
1Openoffice
Apr 29, 2026
Jul 31, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via invalid PLCF data in a DOC document file.