CVE-2025-64406: Apache Openoffice

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a document that would crash the program, or otherwise corrupt other memory areas. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version 4.1.16, which fixes the issue.

Affected products

  • Apache Openoffice: before 4.1.16 (fixed in 4.1.16)

Published 2025-11-12. Last modified 2026-06-17.