VYPR

core

by ONLYOFFICE

CVEs (4)

  • CVE-2023-30187CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.02

    An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.

  • CVE-2021-25829HigMar 1, 2021
    risk 0.49cvss 7.5epss 0.07

    An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacker is able to produce a denial of service attack that can eventually shut down the target server.

  • CVE-2022-29777CriJun 2, 2022
    risk 0.01cvss 9.8epss 0.07

    Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.

  • CVE-2022-29776CriJun 2, 2022
    risk 0.01cvss 9.8epss 0.07

    Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.