CVE-2014-3575: Apache Openoffice

Medium severity, CVSS 4.3. EPSS: 11.3% chance of exploitation in the next 30 days.

The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects.

Affected products

  • Apache Openoffice: before 4.1.1 (fixed in 4.1.1)
  • Libreoffice Libreoffice: before 4.2.6 (fixed in 4.2.6); from 4.3.0, before 4.3.1 (fixed in 4.3.1)
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2014-08-27. Last modified 2026-06-17.