ONLYOFFICE Document Server 4.1.2-37

CPE Details

ONLYOFFICE Document Server 4.1.2-37
4.1.2-37
2020-04-17
16h16 +00:00
2020-04-17
16h16 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:onlyoffice:document_server:4.1.2-37:*:*:*:*:*:*:*

Informations

Vendor

onlyoffice

Product

document_server

Version

4.1.2-37

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-50883 2024-09-08 22h00 +00:00 ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the Function object. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446.
6.1
Medium
CVE-2023-30186 2023-08-13 22h00 +00:00 A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
9.8
Critical
CVE-2023-30187 2023-08-13 22h00 +00:00 An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
9.8
Critical
CVE-2023-30188 2023-08-13 22h00 +00:00 Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.
7.5
High
CVE-2022-48422 2023-03-19 00h00 +00:00 ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current working directory, which may be any directory in which an ONLYOFFICE document is located.
7.8
High
CVE-2022-29777 2022-06-01 10h51 +00:00 Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.
9.8
Critical
CVE-2022-29776 2022-06-01 10h51 +00:00 Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.
9.8
Critical
CVE-2022-24229 2022-04-08 09h06 +00:00 A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML or JavaScript through /example/editor.
6.1
Medium
CVE-2021-25832 2021-03-01 14h08 +00:00 A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker is able to gain remote code executions on DocumentServer.
9.8
Critical
CVE-2021-25831 2021-03-01 14h08 +00:00 A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the conversion of the crafted file from PPTT into PPTX format. Using the chain of two other bugs related to improper string handling, a remote attacker can obtain remote code execution on DocumentServer.
9.8
Critical
CVE-2021-25829 2021-03-01 14h07 +00:00 An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacker is able to produce a denial of service attack that can eventually shut down the target server.
7.5
High
CVE-2021-3199 2021-01-22 01h41 +00:00 Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
9.8
Critical