← Vulnerability feed

Vulnerability record · CVE-2021-33035 · published 23 September 2021

CVE-2021-33035: Apache OpenOffice DBF field buffer overflow allows code execution

Apache · Openoffice

Apache OpenOffice fails to validate the size of certain fields when reading dBase/DBF documents, copying unchecked data into fixed local variables. A crafted DBF file overflows the stack, corrupting return data and enabling arbitrary code execution. The flaw affects OpenOffice up to and including 4.1.10 and matters because document files are a routine, trusted-looking delivery path.

7.8 CVSS 3.1 High EPSS 51% · top 1.1% CWE-120 · Classic buffer overflow
7.8CVSS 3.1 base score, v2 6.8
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS 7.8 with full code execution and high EPSS, though exploitation requires the victim to open a crafted file and no KEV listing exists.

What it is

Apache OpenOffice fails to validate the size of certain fields when reading dBase/DBF documents, copying unchecked data into fixed local variables. A crafted DBF file overflows the stack, corrupting return data and enabling arbitrary code execution. The flaw affects OpenOffice up to and including 4.1.10 and matters because document files are a routine, trusted-looking delivery path.

Impact

An attacker who gets a victim to open a malicious DBF document can execute arbitrary code in the context of the OpenOffice process, giving full control of confidentiality, integrity and availability on that host.

Attack surface

Reached locally by opening a crafted DBF document in Apache OpenOffice; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so the victim must open the file. No network service is exposed by this flaw.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated likelihood of attempted exploitation. References include patch commits and advisories but no public exploit tag.

What to do

  • Upgrade Apache OpenOffice past 4.1.10 to a version containing the fix, or apply the referenced patch commit.
  • If upgrade is not possible, block or restrict opening of untrusted DBF/dBase files in OpenOffice.
  • Treat DBF attachments and downloads from external sources as untrusted; scan and quarantine before opening.
  • Consider migrating users to a maintained office suite if OpenOffice cannot be kept patched.

Detection

  • Monitor for OpenOffice processes spawning unexpected child processes such as cmd.exe, powershell.exe or /bin/sh.
  • Alert on crashes or abnormal terminations of soffice processes when opening DBF files.
  • Log and review file-open events for .dbf files originating from email attachments or downloads.
  • Hunt for DBF files with anomalous field-length metadata or unusually large field values.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-33035 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2014-3524Apache openoffice command injection vulnerabilityApache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc sp…EPSS 15%9.3CVE-2010-3450Apache openoffice path traversal vulnerabilityMultiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a…EPSS 11%9.3CVE-2010-3451Apache openoffice use after free vulnerabilityUse-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica…EPSS 10%9.3CVE-2010-3452Apache openoffice use after free vulnerabilityUse-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica…EPSS 10%9.3CVE-2010-3453Apache openoffice out-of-bounds write vulnerabilityThe WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number…EPSS 9.7%9.3CVE-2010-3454Apache openoffice vulnerabilityMultiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote atta…EPSS 10%9.3CVE-2010-4253Apache openoffice out-of-bounds write vulnerabilityHeap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applicatio…EPSS 10%9.3CVE-2010-4643Apache openoffice out-of-bounds write vulnerabilityHeap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applicatio…EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2021-33035), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.