Apache OpenOffice Security Team Bulletin
If you want to stay up to date on Apache OpenOffice security announcements, please subscribe to our security-alerts mailing list.
Fixed in Apache OpenOffice 4.1.8
- CVE-2020-13958: Unrestricted actions leads to arbitrary code execution in crafted documents
Fixed in Apache OpenOffice 4.1.7
- CVE-2019-9853: Insufficient URL decoding flaw in categorizing macro location
Fixed in Apache OpenOffice 4.1.6
- CVE-2018-11790: Arithmetic overflow and wrap around during string length calculation
Fixed in Apache OpenOffice 4.1.5
- No security vulnerabilities fixed in this release
Fixed in Apache OpenOffice 4.1.4
Fixed in Apache OpenOffice 4.1.3
- CVE-2016-1513: Memory Corruption Vulnerability (Impress Presentations)
- CVE-2016-6803: Windows Installer Can Enable Privileged Trojan Execution
- CVE-2016-6804: Windows Installer Execution of Arbitrary Code with Elevated Privileges
Fixed in Apache OpenOffice 4.1.2
Fixed in Apache OpenOffice 4.1.1
- CVE-2014-3575: Targeted Data Exposure Using Crafted OLE Objects in Apache OpenOffice
- CVE-2014-3524: Calc Command Injection Vulnerability in Apache OpenOffice
Fixed in Apache OpenOffice 4.0.0
- CVE-2013-2189: DOC Memory Corruption Vulnerability in Apache OpenOffice
- CVE-2013-4156: DOCM Memory Corruption Vulnerability in Apache OpenOffice
Fixed in Apache OpenOffice 3.4.1
Fixed in Apache OpenOffice 3.4.0
- CVE-2012-1149: OpenOffice.org integer overflow error in vclmi.dll module when allocating memory for an embedded image object
- CVE-2012-2149: OpenOffice.org memory overwrite vulnerability
- CVE-2012-2334: Vulnerabilities related to malformed Powerpoint files in OpenOffice.org 3.3.0
Patches for OpenOffice.org 3.3
Fixed in OpenOffice.org 3.3
Fixed in OpenOffice.org 3.2.1
- CVE-2009-3555: OpenOffice.org 2 and 3 may be affected by the TLS/SSL Renegotiation Issue in 3rd Party Libraries
- CVE-2010-0395: Security vulnerability in OpenOffice.org related to python scripting
Fixed in OpenOffice.org 3.2
- CVE-2006-4339: Potential vulnerability from 3rd party libxml2 libraries
- CVE-2009-0217: Potential vulnerability from 3rd party libxmlsec libraries
- CVE-2009-2493: OpenOffice.org 3 for Windows bundles a vulnerable version of MSVC Runtime
- CVE-2009-2949: Potential vulnerability related to XPM file processing
- CVE-2009-2950: Potential vulnerability related to GIF file processing
- CVE-2009-3301/2: Potential vulnerability related to MS-Word document processing
Fixed in OpenOffice.org 3.1.1
Fixed in OpenOffice.org 3.1
- No security vulnerabilities fixed in this release
Fixed in OpenOffice.org 3.0.1
- No security vulnerabilities fixed in this release
Fixed in OpenOffice.org 3.0
- No security vulnerabilities fixed in this release
Fixed in OpenOffice.org 2.4.3
Fixed in OpenOffice.org 2.4.2
- CVE-2008-2237: Manipulated WMF files can lead to heap overflows and arbitrary code execution
- CVE-2008-2238: Manipulated EMF files can lead to heap overflows and arbitrary code execution
Fixed in OpenOffice.org 2.4.1
- CVE-2008-2152: Different kinds of manipulated files may lead to heap overflows and arbitrary code execution
Fixed in OpenOffice.org 2.4
- CVE-2007-4770/4771: Manipulated ODF text documents containing XForms can lead to heap overflows and arbitrary code execution
- CVE-2007-5745/5747: Manipulated Quattro Pro files can lead to heap overflows and arbitrary code execution
- CVE-2007-5746: Manipulated EMF files can lead to heap overflows and arbitrary code execution
- CVE-2008-0320: Manipulated OLE files can lead to heap overflows and arbitrary code execution
Fixed in OpenOffice.org 2.3.1
- CVE-2007-4575: Potential arbitrary code execution vulnerability in 3rd party module (HSQLDB)
Fixed in OpenOffice.org 2.3
- CVE-2007-2834: Manipulated TIFF files can lead to heap overflows and arbitrary code execution
Fixed in OpenOffice.org 2.2.1
- CVE-2007-2754: Integer overflow and heap-based buffer overflow vulnerability in 3rd party module (freetype)
- CVE-2007-0245: Manipulated RTF files can lead to heap overflows and arbitrary code execution
Fixed in OpenOffice.org 2.2
Fixed in OpenOffice.org 2.1
Fixed in OpenOffice.org 2.0.3
Security Home ->
Bulletin