Apache OpenOffice v4.1.16 及更早版本中存在的 Java 集成代码执行漏洞,允许攻击者通过构造恶意不受信任的文档,在用户打开该文档时触发任意代码(包括远程代码)的执行。 该问题预计将在版本 4.1.17 中得到修复,该版本目前正处于发布候选(RC)阶段。 在此版本正式发布前,用户可以通过在“首选项”对话框中禁用 Java 运行时集成来缓解此问题,从而阻止攻击。如果无法禁用 Java 集成,或出于额外安全考虑,建议完全避免打开来源不受信任的文件。待 4.1.17 版本正式发布后,请升级至该版本
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache OpenOffice | 0 ~ 4.1.16 | - |
|
| Apache Software Foundation | Apache OpenOffice | 0 ~ 95923fd437e06edd38a4f0e139a27c755a6f3ba6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102795 | 9.3 CRITICAL | Apache Traffic Server: SNI to Host header matching policy is not properly enforced |
| CVE-2026-83632 | 9.2 CRITICAL | Apache Thrift: C++ THttpTransport grows its line buffer without bound |
| CVE-2026-91135 | 9.2 CRITICAL | Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction) |
| CVE-2026-86535 | 8.7 HIGH | Apache Thrift: A JSON member name can stall the Node server's event loop indefinitely |
| CVE-2026-66858 | 8.7 HIGH | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: |
| CVE-2026-66837 | 8.7 HIGH | Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string length |
| CVE-2026-94658 | 8.7 HIGH | Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read ( |
| CVE-2026-94646 | 8.7 HIGH | Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two tri |
| CVE-2026-94633 | 8.7 HIGH | Apache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre-versioned na |
| CVE-2026-87117 | 8.7 HIGH | Apache Thrift: PHP `thrift_protocol` accelerator dereferences a missing container-element |
| CVE-2026-86537 | 8.7 HIGH | Apache Thrift: A truncated HTTP request stops the D library's server, allowing an unauthen |
| CVE-2026-93926 | 8.7 HIGH | Apache Thrift: C++ `THeaderTransport::untransform()` leaks the zlib stream on the error pa |
| CVE-2026-94642 | 8.7 HIGH | Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transport exception |
| CVE-2026-85493 | 8.7 HIGH | Apache Thrift, Apache Thrift: TProtocolUtil.skip follows peer-chosen nesting to any depth |
| CVE-2026-93925 | 8.7 HIGH | Apache Thrift: C++ `THeaderTransport::writeVarint32()` stack buffer overflow on a negative |
| CVE-2026-91137 | 8.7 HIGH | Apache Thrift: PHP `thrift_protocol` accelerator: zero-byte container elements |
| CVE-2026-85494 | 8.7 HIGH | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, |
| CVE-2026-82458 | 8.7 HIGH | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, |
| CVE-2026-96294 | 8.7 HIGH | Apache Thrift: nodejs web server: no `error` listener on an upgraded WebSocket connection |
| CVE-2026-61373 | 8.7 HIGH | Apache Thrift: Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation |
Showing top 20 of 69 CVEs. View all on vendor page → →
No comments yet