CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,847 CVEs tracked 53,242 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,918 Nuclei templates 37,802 vendors 42,493 researchers
60 results Clear all
CVE-2012-5639 6.5 MEDIUM EPSS 0.00
LibreOffice/OpenOffice - Info Disclosure
LibreOffice and OpenOffice automatically open embedded content
CWE-668 Dec 20, 2019
CVE-2011-2177 7.8 HIGH EPSS 0.02
OpenOffice.org <3.3 - RCE
OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.
Nov 27, 2019
CVE-2018-11790 7.8 HIGH 1 PoC EPSS 0.01
Apache Open Office <4.1.5 - Memory Corruption
When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string length calculation.
CWE-682 Jan 31, 2019
CVE-2018-10583 7.5 HIGH 5 PoCs Analysis EPSS 0.72
LibreOffice 6.0.3 - Apache OpenOffice Writer 4.1.5 - Info Disclosure
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.
CWE-200 May 01, 2018
CVE-2017-3157 5.5 MEDIUM EPSS 0.01
Apache Openoffice < 4.1.3 - Information Disclosure
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send the document back to the attacker. The vulnerability is mitigated by the need for the attacker to know the precise file path in the target system, and the need to trick the user into saving the document and sending it back.
CWE-200 Nov 20, 2017
CVE-2017-12608 7.8 HIGH EPSS 0.01
Apache Openoffice < 4.1.4 - Out-of-Bounds Write
A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.
CWE-787 Nov 20, 2017
CVE-2017-12607 7.8 HIGH EPSS 0.01
Apache Openoffice < 4.1.4 - Out-of-Bounds Write
A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.
CWE-787 Nov 20, 2017
CVE-2017-9806 7.8 HIGH EPSS 0.01
OpenOffice Writer <4.1.4 - Memory Corruption
A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.
CWE-787 Nov 20, 2017
CVE-2016-6804 7.8 HIGH EPSS 0.00
Apache Openoffice < 4.1.3 - Access Control
The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that allows execution of arbitrary code with elevated privileges. This requires that the location in which the installer is run has been previously poisoned by a file that impersonates a dynamic-link library that the installer depends upon.
CWE-264 Nov 20, 2017
CVE-2016-6803 7.8 HIGH EPSS 0.00
Apache Openoffice < 4.1.2 - Untrusted Search Path
An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for Windows. The PC must have previously been infected by a Trojan Horse application (or user) running with administrative privilege. Any installer with the unquoted search path vulnerability becomes a delayed trigger for the exploit.
CWE-426 Nov 13, 2017
CVE-2016-1513 7.8 HIGH EPSS 0.01
Apache OpenOffice <4.1.2 - RCE
The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute arbitrary code via crafted MetaActions in an (1) ODP or (2) OTP file.
CWE-125 Aug 05, 2016
CVE-2015-5214 EPSS 0.36
LibreOffice <4.4.6,5.x <5.0.1 & Apache OpenOffice <4.1.2 - RCE
LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via an index to a non-existent bookmark in a DOC file.
CWE-119 Nov 10, 2015
CVE-2015-5213 EPSS 0.23
LibreOffice <4.4.5/Apache OpenOffice <4.1.2 - Memory Corruption
Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.
CWE-189 Nov 10, 2015
CVE-2015-5212 EPSS 0.50
LibreOffice <4.4.5 & Apache OpenOffice <4.1.2 - Memory Corruption
Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via crafted PrinterSetup data in an ODF document.
CWE-191 Nov 10, 2015
CVE-2015-4551 EPSS 0.10
Libreoffice < 4.4.4 - Information Disclosure
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.
CWE-200 Nov 10, 2015
CVE-2015-1774 EPSS 0.13
Canonical Ubuntu Linux < 4.1.1 - Out-of-Bounds Write
The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.
CWE-787 Apr 28, 2015
CVE-2014-3575 EPSS 0.10
Redhat Enterprise Linux Desktop < 4.1.1 - Information Disclosure
The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects.
CWE-200 Aug 27, 2014
CVE-2014-3524 EPSS 0.12
Apache Openoffice < 4.1.1 - Command Injection
Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.
CWE-77 Aug 26, 2014
CVE-2013-4156 EPSS 0.01
Apache Openoffice < 4.0.0 - Out-of-Bounds Write
Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted element in an OOXML document file.
CWE-787 Jul 31, 2013
CVE-2013-2189 EPSS 0.01
Apache Openoffice < 4.0.0 - Out-of-Bounds Write
Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via invalid PLCF data in a DOC document file.
CWE-787 Jul 31, 2013