peter bassill · operator
$ cve CVE-2022-29777 JSON

CVE-2022-29777

9.8
CRITICAL · CVSS 3.1 · EPSS 6.9% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.91% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploitnone known
Published2022-06-02
Last modified2026-06-17

Affected (2)

VendorProduct
onlyofficecore
onlyofficedocument server

References

→ the Explorer  ·  watch your stack  ·  NVD