CVE Explorer
CVE-2025-64402
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links
to be loaded without prompt. In the affected versions of Apache OpenOffice, documents that used "OLE objects" linked to external files would
load the contents of those files without prompting the user for
permission to do so.
This issue affects Apache OpenOffice: through 4.1.15.
Users are recommended to upgrade to v
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Apache OpenOffice","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"4.1.15","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:52f6610348775a4958434cf739859b2af5f8606767edfba560e6befe58e9d133 · sha256:fb4a3c4d070ff9ad… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:52f6610348775a4958434cf739859b2af5f8606767edfba560e6befe58e9d133 · sha256:fb4a3c4d070ff9ad… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:52f6610348775a4958434cf739859b2af5f8606767edfba560e6befe58e9d133 · sha256:fb4a3c4d070ff9ad… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"url":"http://www.openwall.com/lists/oss-security/2025/11/11/5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f6610348775a4958434cf739859b2af5f8606767edfba560e6befe58e9d133 · sha256:fb4a3c4d070ff9ad… · /containers/adp/0/references/0
{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/tssrl88tygjsgk6csllm6p2fb6tlv8d8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f6610348775a4958434cf739859b2af5f8606767edfba560e6befe58e9d133 · sha256:fb4a3c4d070ff9ad… · /containers/cna/references/1
{"tags":["vendor-advisory"],"url":"https://www.openoffice.org/security/cves/CVE-2025-64402.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52f6610348775a4958434cf739859b2af5f8606767edfba560e6befe58e9d133 · sha256:fb4a3c4d070ff9ad… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.