CVE-2025-64403HIGH 8.1EPSS p67.0%

CVE-2025-64403CVE-2025-64403

Description

Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause such links to be loaded without prompt. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version 4.1.16, which fixes the issue.

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS1.31% probability of exploitation · percentile 67.0% · 2026-06-19T12:03:05Z
Published2025-11-12
Last modified2025-11-13

Underlying weaknesses· 1

CWE-862

References

  1. https://lists.apache.org/thread/t7c6jhvdb00xtgd9vvn7h5sq9f4h5trt
  2. https://www.openoffice.org/security/cves/CVE-2025-64403.html
  3. http://www.openwall.com/lists/oss-security/2025/11/11/6

1

TypeTargetConfidenceTier
WeaknessMissing Authorizationcwe-8620%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-44822
CVE
CVE-2026-45455
CVE
CVE-2025-47167
CVE
CVE-2026-40421
CVE
CVE-2026-45459
CVE
CVE-2025-49696
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.