Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache OpenOffice — Vulnerabilities & Security Advisories 27

All 27 CVE vulnerabilities found in Apache OpenOffice, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting Apache OpenOffice, focusing on specific weakness types such as memory corruption, privilege escalation, and remote code execution. The collection compiles historical and recent advisories that document confirmed flaws within the product. Users can track the vendor's advisory history, analyze the impact of a particular weakness class, and review the complete vulnerability record for this open-source office suite.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2025-64407 Apache OpenOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variables CWE-862 4.0 - 2025-11-12
CVE-2025-64406 Apache OpenOffice: Possible memory corruption during CSV import CWE-787 7.7 - 2025-11-12
CVE-2025-64405 Apache OpenOffice: Remote documents loaded without prompt via DDE function CWE-862 6.2 - 2025-11-12
CVE-2025-64404 Apache OpenOffice: Remote documents loaded without prompt via background and bullet images CWE-862 6.8 - 2025-11-12
CVE-2025-64403 Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc CWE-862 4.0 - 2025-11-12
CVE-2025-64402 Apache OpenOffice: Remote documents loaded without prompt via OLE objects CWE-862 6.2 - 2025-11-12
CVE-2025-64401 Apache OpenOffice: Remote documents loaded without prompt via IFrame CWE-862 7.7 - 2025-11-12
CVE-2023-47804 Apache OpenOffice: Macro URL arbitrary script execution CWE-20 7.8 - 2023-12-29
CVE-2022-47502 Apache OpenOffice: Macro URL arbitrary script execution CWE-20 7.3 - 2023-03-24
CVE-2022-38745 Apache OpenOffice: Empty entry in Java class path CWE-94 9.8 - 2023-03-24
CVE-2022-37401 Apache OpenOffice Weak Master Keys CWE-331 8.8 - 2022-08-13
CVE-2022-37400 Apache OpenOffice Static Initialization Vector Allows to Recover Passwords for Web Connections Without Knowing the Master Password CWE-330 6.5 - 2022-08-13
CVE-2021-41832 Content Manipulation with Certificate Validation Attack CWE-347 7.5 - 2021-10-11
CVE-2021-41831 Timestamp Manipulation with Signature Wrapping CWE-347 4.0 - 2021-10-11
CVE-2021-41830 Double Certificate Attack CWE-347 7.5 - 2021-10-11
CVE-2021-40439 Billion Laughs CWE-611 8.1 - 2021-10-07
CVE-2021-28129 DEB packaging for Apache OpenOffice 4.1.8 installed with a non-root userid and groupid CWE-284 7.1 - 2021-10-07
CVE-2021-33035 Buffer overflow from a crafted DBF file CWE-120 7.8 - 2021-09-23
CVE-2021-30245 Code execution in Apache OpenOffice via non-http(s) schemes in Hyperlinks 8.8 - 2021-04-15
CVE-2020-13958 Apache OpenOffice 安全漏洞 7.8 - 2020-11-17
CVE-2018-11790 Apache OpenOffice 安全漏洞 7.8 - 2019-01-31
CVE-2017-3157 Apache OpenOffice Calc和Writer 安全漏洞 6.5 - 2017-11-20
CVE-2017-12608 Apache OpenOffice文字处理器应用程序安全漏洞 7.8 - 2017-11-20
CVE-2017-12607 Apache OpenOffice 安全漏洞 7.8 - 2017-11-20
CVE-2017-9806 Apache OpenOffice文字处理器应用程序安全漏洞 7.8 - 2017-11-20
CVE-2016-6804 Apache OpenOffice for Windows安装程序安全漏洞 7.8 - 2017-11-20
CVE-2016-6803 Apache OpenOffice for Windows 安全漏洞 7.8 - 2017-11-13

All 27 known CVE vulnerabilities affecting Apache OpenOffice with full Chinese analysis, references, and POCs where available.