Critical severity9.8NVD Advisory· Published Jun 2, 2022· Updated Jun 17, 2026
CVE-2022-29777
CVE-2022-29777
Description
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:onlyoffice:core:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:onlyoffice:core:*:*:*:*:*:*:*:*range: <=6.1.0.26
- (no CPE)range: <=6.1.0.26
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=6.0.0
Patches
Vulnerability mechanics
References
3- github.com/ONLYOFFICE/core/commit/b17d5e860f30e8be2caeb0022b63be4c76660178nvdPatchThird Party Advisory
- github.com/moehw/poc_exploits/tree/master/CVE-2022-29777nvdExploitThird Party Advisory
- github.com/ONLYOFFICE/DocumentServer/blob/master/CHANGELOG.mdnvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.