CVE-2022-29777
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.
- Affected products
- Onlyoffice Core, Onlyoffice Document Server
- Onlyoffice Core
- ≤ 6.1.0.26
- Onlyoffice Document Server
- ≤ 6.0.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 7.0% (94th percentile)
- Weakness
- CWE-787
- NVD status
- Modified
- Published
- 2022-06-01
CVE-2022-29777 at NVD
No indexed exploits for CVE-2022-29777 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-29777 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.