ONLYOFFICE Document Server 5.6.2

CPE Details

ONLYOFFICE Document Server 5.6.2
5.6.2
2021-02-02
17h57 +00:00
2021-02-02
17h57 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:onlyoffice:document_server:5.6.2:*:*:*:*:*:*:*

Informations

Vendor

onlyoffice

Product

document_server

Version

5.6.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-50883 2024-09-08 22h00 +00:00 ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the Function object. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446.
6.1
Medium
CVE-2023-30186 2023-08-13 22h00 +00:00 A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
9.8
Critical
CVE-2023-30187 2023-08-13 22h00 +00:00 An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
9.8
Critical
CVE-2023-30188 2023-08-13 22h00 +00:00 Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.
7.5
High
CVE-2022-48422 2023-03-19 00h00 +00:00 ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current working directory, which may be any directory in which an ONLYOFFICE document is located.
7.8
High
CVE-2022-29777 2022-06-01 10h51 +00:00 Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.
9.8
Critical
CVE-2022-29776 2022-06-01 10h51 +00:00 Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.
9.8
Critical
CVE-2022-24229 2022-04-08 09h06 +00:00 A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML or JavaScript through /example/editor.
6.1
Medium
CVE-2021-25832 2021-03-01 14h08 +00:00 A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker is able to gain remote code executions on DocumentServer.
9.8
Critical
CVE-2021-25831 2021-03-01 14h08 +00:00 A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the conversion of the crafted file from PPTT into PPTX format. Using the chain of two other bugs related to improper string handling, a remote attacker can obtain remote code execution on DocumentServer.
9.8
Critical
CVE-2021-25830 2021-03-01 14h07 +00:00 A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker can achieve remote code execution on DocumentServer.
9.8
Critical
CVE-2021-25829 2021-03-01 14h07 +00:00 An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacker is able to produce a denial of service attack that can eventually shut down the target server.
7.5
High
CVE-2021-3199 2021-01-22 01h41 +00:00 Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
9.8
Critical