Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
onlyoffice document server vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2022-29776
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.
Onlyoffice Core
Onlyoffice Document Server
1 Github repository
9.8
CVSSv3
CVE-2022-29777
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.
Onlyoffice Core
Onlyoffice Document Server
1 Github repository
9.8
CVSSv3
CVE-2023-30186
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 up to and including 7.3.2 allows remote malicious users to run arbitrary code via crafted JavaScript file.
Onlyoffice Document Server
9.8
CVSSv3
CVE-2023-30187
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 up to and including 7.3.2 allows remote malicious users to run arbitrary code via crafted JavaScript file.
Onlyoffice Document Server
7.5
CVSSv3
CVE-2023-30188
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 up to and including 7.3.2 allows remote malicious users to cause a denial of service via crafted JavaScript file.
Onlyoffice Document Server
7.8
CVSSv3
CVE-2022-48422
ONLYOFFICE Docs up to and including 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current working directory, which may be any directory in which an ONLYOFFICE document is located.
Onlyoffice Document Server
9.8
CVSSv3
CVE-2021-3199
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server prior to 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
Onlyoffice Document Server
1 Github repository
6.1
CVSSv3
CVE-2022-24229
A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML or JavaScript through /example/editor.
Onlyoffice Document Server
7.5
CVSSv3
CVE-2021-25829
An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacker is able to produce a denial of service attack that can eventually shut down the target server.
Onlyoffice Document Server
9.8
CVSSv3
CVE-2021-25830
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker...
Onlyoffice Document Server
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-30078
CVE-2024-37896
code injection
CVE-2024-3080
CVE-2024-5172
cross-site request forgery
CVE-2024-6111
firmware
CVE-2024-38504
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »