High severity7.5NVD Advisory· Published Mar 1, 2021· Updated Jun 17, 2026
CVE-2021-25829
CVE-2021-25829
Description
An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacker is able to produce a denial of service attack that can eventually shut down the target server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: v4.0.0-9-v5.6.3
v4.0.0-9-v5.6.3+ 2 more
- (no CPE)range: v4.0.0-9-v5.6.3
- (no CPE)
- cpe:2.3:a:onlyoffice:document_server:*:*:*:*:*:*:*:*range: >=4.0.0-9,<=5.6.3
Patches
Vulnerability mechanics
References
8- github.com/merrychap/poc_exploits/tree/master/ONLYOFFICE/CVE-2021-25829nvdExploitThird Party Advisory
- github.com/ONLYOFFICE/core/blob/c1e4a2ce33bdcfab29d670f5fdb10fc63cf5fd6a/ASCOfficePPTXFile/PPTXFormat/Comments.hnvdVendor Advisory
- github.com/ONLYOFFICE/core/blob/c1e4a2ce33bdcfab29d670f5fdb10fc63cf5fd6a/ASCOfficePPTXFile/PPTXFormat/Core.hnvdVendor Advisory
- github.com/ONLYOFFICE/core/blob/c1e4a2ce33bdcfab29d670f5fdb10fc63cf5fd6a/ASCOfficePPTXFile/PPTXFormat/NotesMaster.hnvdVendor Advisory
- github.com/ONLYOFFICE/core/blob/c1e4a2ce33bdcfab29d670f5fdb10fc63cf5fd6a/ASCOfficePPTXFile/PPTXFormat/NotesSlide.hnvdVendor Advisory
- github.com/ONLYOFFICE/core/blob/c1e4a2ce33bdcfab29d670f5fdb10fc63cf5fd6a/ASCOfficePPTXFile/PPTXFormat/Presentation.hnvdVendor Advisory
- github.com/ONLYOFFICE/core/blob/c1e4a2ce33bdcfab29d670f5fdb10fc63cf5fd6a/ASCOfficePPTXFile/PPTXFormat/Theme.hnvdVendor Advisory
- github.com/ONLYOFFICE/core/blob/v5.6.4.10/ASCOfficePPTXFile/Editor/BinaryFileReaderWriter.cppnvdVendor Advisory
News mentions
0No linked articles in our index yet.