High severity8.1NVD Advisory· Published Nov 12, 2025· Updated Jun 17, 2026
CVE-2025-64403
CVE-2025-64403
Description
Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause such links to be loaded without prompt.
This issue affects Apache OpenOffice: through 4.1.15.
Users are recommended to upgrade to version 4.1.16, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: <=4.1.15
<=4.1.15+ 2 more
- (no CPE)range: <=4.1.15
- (no CPE)range: 0
- cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:*range: <4.1.16
Patches
Vulnerability mechanics
References
3- www.openwall.com/lists/oss-security/2025/11/11/6nvdMailing ListThird Party Advisory
- lists.apache.org/thread/t7c6jhvdb00xtgd9vvn7h5sq9f4h5trtnvdMailing ListVendor Advisory
- www.openoffice.org/security/cves/CVE-2025-64403.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.