VendorsApacheopenofficeany version
Vulnerabilities

Apache Software Foundation OpenOffice any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

55CVEs
CVE-2014-3524
Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.
Published 2014-08-26 · Modified
9.3EPSS 0.145
CVE-2009-2949
Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.
Published 2010-02-16 · Modified
9.3EPSS 0.142
CVE-2009-2950
Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression.
Published 2010-02-16 · Modified
9.3EPSS 0.136
CVE-2009-3301
Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.
Published 2010-02-16 · Modified
9.3EPSS 0.120
CVE-2007-2834
Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.
Published 2007-09-18 · Modified
9.3EPSS 0.120
CVE-2009-3302
filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTSetBrc table property modifier in a Word document, related to a "boundary error flaw."
Published 2010-02-16 · Modified
9.3EPSS 0.117
CVE-2010-3450
Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filter description file, (2) an Extension (aka OXT) file, or unspecified other (3) JAR or (4) ZIP files.
Published 2011-01-28 · Modified
9.3EPSS 0.107
CVE-2010-0395
OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.
Published 2010-06-10 · Modified
9.3EPSS 0.105
CVE-2010-3451
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via malformed tables in an RTF document.
Published 2011-01-28 · Modified
9.3EPSS 0.103
CVE-2010-3452
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document.
Published 2011-01-28 · Modified
9.3EPSS 0.103
CVE-2010-3454
Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
Published 2011-01-28 · Modified
9.3EPSS 0.103
CVE-2010-4643
Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.
Published 2011-01-28 · Modified
9.3EPSS 0.101
CVE-2010-4253
Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document.
Published 2011-01-28 · Modified
9.3EPSS 0.101
CVE-2010-3453
The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
Published 2011-01-28 · Modified
9.3EPSS 0.097
CVE-2016-6804
The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that allows execution of arbitrary code with elevated privileges. This requires that the location in which the installer is run has been previously poisoned by a file that impersonates a dynamic-link library that the installer depends upon.
Published 2017-11-20 · Modified
9.3EPSS 0.030
CVE-2020-13958
A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks pointing to an executable on the target users file system. These hyperlinks can be triggered unconditionally. In fixed versions no internal protocol may be called from the document event handler and other hyperlinks require a control-click.
Published 2020-11-17 · Modified
9.3EPSS 0.029
CVE-2016-6803
An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for Windows. The PC must have previously been infected by a Trojan Horse application (or user) running with administrative privilege. Any installer with the unquoted search path vulnerability becomes a delayed trigger for the exploit.
Published 2017-11-13 · Modified
9.3EPSS 0.021
CVE-2021-30245
Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks
Published 2021-04-15 · Modified
8.8EPSS 0.049
CVE-2023-47804
Apache OpenOffice: Macro URL arbitrary script execution
Published 2023-12-29 · Modified
8.8EPSS 0.027
CVE-2022-37401
Apache OpenOffice Weak Master Keys
Published 2022-08-13 · Modified
8.8EPSS 0.018
CVE-2022-37400
Apache OpenOffice Static Initialization Vector Allows to Recover Passwords for Web Connections Without Knowing the Master Password
Published 2022-08-13 · Modified
8.8EPSS 0.009
CVE-2025-64403
Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc
Published 2025-11-12 · Analyzed
8.1EPSS 0.012
CVE-2021-33035
Buffer overflow from a crafted DBF file
Published 2021-09-23 · Modified
7.8EPSS 0.506
CVE-2016-1513
The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute arbitrary code via crafted MetaActions in an (1) ODP or (2) OTP file.
Published 2016-08-05 · Modified
7.8EPSS 0.043
CVE-2017-12608
A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.
Published 2017-11-20 · Modified
7.8EPSS 0.029
CVE-2017-12607
A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.
Published 2017-11-20 · Modified
7.8EPSS 0.026
CVE-2017-9806
A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.
Published 2017-11-20 · Modified
7.8EPSS 0.018
CVE-2018-11790
When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string length calculation.
Published 2019-01-31 · Modified
7.8EPSS 0.010
CVE-2022-47502
Apache OpenOffice: Macro URL arbitrary script execution
Published 2023-03-24 · Modified
7.8EPSS 0.010
CVE-2022-38745
Apache OpenOffice: Empty entry in Java class path
Published 2023-03-24 · Modified
7.8EPSS 0.009
CVE-2012-2665
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.
Published 2012-08-06 · Modified
7.5EPSS 0.070
CVE-2010-4494
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
Published 2010-12-07 · Modified
7.5EPSS 0.059
CVE-2025-64405
Apache OpenOffice: Remote documents loaded without prompt via DDE function
Published 2025-11-12 · Modified
7.5EPSS 0.014
CVE-2021-41830
Double Certificate Attack
Published 2021-10-11 · Modified
7.5EPSS 0.014
CVE-2021-41832
Content Manipulation with Certificate Validation Attack
Published 2021-10-11 · Modified
7.5EPSS 0.013
CVE-2025-64404
Apache OpenOffice: Remote documents loaded without prompt via background and bullet images
Published 2025-11-12 · Modified
7.5EPSS 0.012
CVE-2025-64401
Apache OpenOffice: Remote documents loaded without prompt via IFrame
Published 2025-11-12 · Analyzed
7.5EPSS 0.009
CVE-2010-3689
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Published 2011-01-28 · Modified
6.9EPSS 0.007
CVE-2015-5213
Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.
Published 2015-11-10 · Modified
6.8EPSS 0.129
CVE-2004-0179
Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.
Published 2004-04-16 · Modified
6.81 PoCEPSS 0.111
1 / 2Next →