Out-of-Bounds Write Vulnerability in Apache OpenOffice
CVE-2025-64406

4.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
12 November 2025

What is CVE-2025-64406?

An out-of-bounds write vulnerability in Apache OpenOffice could enable attackers to design crafted documents that may lead to crashes or memory corruption. This affects versions through 4.1.15 of the software, potentially putting user data at risk. Users are advised to upgrade to version 4.1.16 immediately to mitigate these risks and ensure software integrity.

Affected Version(s)

Apache OpenOffice 0 <= 4.1.15

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Damjan Jovanovic for discovering, reporting and fixing the issue
.