Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
document server vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2021-25833
A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. Using this vulnerability, a remote attacker can obtain ...
Onlyoffice Document Server
NA
CVE-2023-30186
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 up to and including 7.3.2 allows remote malicious users to run arbitrary code via crafted JavaScript file.
Onlyoffice Document Server
NA
CVE-2023-30187
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 up to and including 7.3.2 allows remote malicious users to run arbitrary code via crafted JavaScript file.
Onlyoffice Document Server
NA
CVE-2023-30188
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 up to and including 7.3.2 allows remote malicious users to cause a denial of service via crafted JavaScript file.
Onlyoffice Document Server
7.5
CVSSv2
CVE-2020-11534
An issue exists in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the NSFileDownloader function to pass parameters to a binary (such as curl or wget) and remotely execute code on a victim's server.
Onlyoffice Document Server 5.5.0
7.5
CVSSv2
CVE-2020-11537
A SQL Injection issue exists in ONLYOFFICE Document Server 5.5.0. An attacker can execute arbitrary SQL queries via injection to DocID parameter of Websocket API.
Onlyoffice Document Server 5.5.0
2.6
CVSSv2
CVE-2006-1788
Adobe Document Server for Reader Extensions 6.0, during log on, provides different error messages depending on whether the user ID is valid or invalid, which allows remote malicious users to more easily identify valid user IDs via brute force attacks.
Adobe Document Server 6.0
7.5
CVSSv2
CVE-2020-11535
An issue exists in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit XML injection to enter an attacker-controlled parameter into the x2t binary, to rewrite this binary and/or libxcb.so.1, and execute code on a victim's server.
Onlyoffice Document Server 5.5.0
2.1
CVSSv2
CVE-2006-1785
Adobe Document Server for Reader Extensions 6.0 allows remote authenticated users to inject arbitrary web script via a leading (1) ftp or (2) http URI in the ReaderURL variable in the "Update Download Site" section of ads-readerext. NOTE: it is not clear whether the ven...
Adobe Document Server 6.0
2.6
CVSSv2
CVE-2006-1787
Adobe Document Server for Reader Extensions 6.0 includes a user's session (jsession) ID in the HTTP Referer header, which allows remote malicious users to gain access to PDF files that are being processed within that session.
Adobe Document Server 6.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22460
CVE-2024-4646
CVE-2024-29212
IMAP
CVE-2023-36672
CVE-2024-34547
command injection
CVE-2024-4651
stored XSS
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »