Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
document server vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-30186
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 up to and including 7.3.2 allows remote malicious users to run arbitrary code via crafted JavaScript file.
Onlyoffice Document Server
NA
CVE-2023-30187
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 up to and including 7.3.2 allows remote malicious users to run arbitrary code via crafted JavaScript file.
Onlyoffice Document Server
NA
CVE-2023-30188
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 up to and including 7.3.2 allows remote malicious users to cause a denial of service via crafted JavaScript file.
Onlyoffice Document Server
4.3
CVSSv2
CVE-2022-24229
A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML or JavaScript through /example/editor.
Onlyoffice Document Server
2.1
CVSSv2
CVE-2006-1785
Adobe Document Server for Reader Extensions 6.0 allows remote authenticated users to inject arbitrary web script via a leading (1) ftp or (2) http URI in the ReaderURL variable in the "Update Download Site" section of ads-readerext. NOTE: it is not clear whether the ven...
Adobe Document Server 6.0
7.5
CVSSv2
CVE-2020-11536
An issue exists in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the unzip function to rewrite a binary and remotely execute code on a victim's server.
Onlyoffice Document Server 5.5.0
2.6
CVSSv2
CVE-2006-1788
Adobe Document Server for Reader Extensions 6.0, during log on, provides different error messages depending on whether the user ID is valid or invalid, which allows remote malicious users to more easily identify valid user IDs via brute force attacks.
Adobe Document Server 6.0
7.5
CVSSv2
CVE-2020-11534
An issue exists in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the NSFileDownloader function to pass parameters to a binary (such as curl or wget) and remotely execute code on a victim's server.
Onlyoffice Document Server 5.5.0
7.5
CVSSv2
CVE-2020-11537
A SQL Injection issue exists in ONLYOFFICE Document Server 5.5.0. An attacker can execute arbitrary SQL queries via injection to DocID parameter of Websocket API.
Onlyoffice Document Server 5.5.0
7.5
CVSSv2
CVE-2020-11535
An issue exists in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit XML injection to enter an attacker-controlled parameter into the x2t binary, to rewrite this binary and/or libxcb.so.1, and execute code on a victim's server.
Onlyoffice Document Server 5.5.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2006-4304
CVE-2024-4240
arbitrary
CVE-2024-31601
XSS
CVE-2023-20198
CVE-2024-4256
CVE-2024-3342
encryption
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »