Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29777.json"
"2026-04-11T23:15:00Z"
[
{
"deprecated": false,
"target": {
"file": "DesktopEditor/fontengine/fontconverter/FontFileType1.cpp",
"function": "CFontFileType1::Parse"
},
"signature_type": "Function",
"digest": {
"function_hash": "142753089591770754154617553089926187992",
"length": 7818.0
},
"signature_version": "v1",
"source": "https://github.com/onlyoffice/core/commit/b17d5e860f30e8be2caeb0022b63be4c76660178",
"id": "CVE-2022-29777-01fe8dd8"
},
{
"deprecated": false,
"target": {
"file": "DesktopEditor/fontengine/fontconverter/FontFileType1.cpp"
},
"signature_type": "Line",
"digest": {
"line_hashes": [
"195675857553038970891917239587558091266",
"307079025787653454369453705177439212106",
"326929395255692644567365719605551926903",
"177670000603626930289428984417385693702",
"284418857521156351939999183149351347225",
"220737760471145691375688268790451100685",
"24140448306519123240357259026541099391",
"114815795101502716424943481420296888295",
"236309202051872469337425367631546674895",
"233630119359192124192428634062867085412",
"310944652577989374812189323787942178076",
"144337639203122240956761186170209785119"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://github.com/onlyoffice/core/commit/b17d5e860f30e8be2caeb0022b63be4c76660178",
"id": "CVE-2022-29777-04d15bb1"
},
{
"deprecated": false,
"target": {
"file": "DesktopEditor/fontengine/fontconverter/FontFileType1.cpp",
"function": "CFontFileType1::RemovePfbMarkers"
},
"signature_type": "Function",
"digest": {
"function_hash": "274665100157578112167350080433985304819",
"length": 896.0
},
"signature_version": "v1",
"source": "https://github.com/onlyoffice/core/commit/b17d5e860f30e8be2caeb0022b63be4c76660178",
"id": "CVE-2022-29777-23227d9f"
},
{
"deprecated": false,
"target": {
"file": "DesktopEditor/fontengine/fontconverter/FontFileBase.h"
},
"signature_type": "Line",
"digest": {
"line_hashes": [
"93742985943237460373566265526080858904",
"318229423779305748891770034022181468533",
"110345666770836520708792355838852100169",
"332149651212070112418204479874536566831",
"283702463392352073381560451047372201282",
"262917627158786860327576651854257156523",
"291541302888007927364377572086128978842",
"208328547864226911783550703716458577012",
"54337494756917250036097115412944409831",
"228832883154323824489601008383861152099",
"293834089521211862750126377264567921934",
"260592570427547285218175734016939186",
"336759514856087193743766177743884243352",
"130013125822573304883342994154930239901",
"37766952930944036253852876133897859047",
"312899540810565650710089840773039955830",
"293834089521211862750126377264567921934",
"260592570427547285218175734016939186",
"167544892119218561764171315603659799678",
"239574410827491671778668034927414495701",
"234661403181037796808015882728216384748",
"184102228452463514909184993230606259341",
"13979567168732274848852943625667478688",
"166671368885431670123508945280632987949",
"282901428733219177551918888376452105276",
"323721734799643249539327812492272304849",
"35137918778388455873910894733182241518",
"252599287533317523943557962842283790841",
"13979567168732274848852943625667478688",
"166671368885431670123508945280632987949",
"216817157689063913435484258906783634517",
"201601688222535977631192704566708116577",
"151512855944972411149279648514906207078",
"125717647147379166916705799708938303657",
"163039322464806677423007812268690881131",
"1093563972894592167501698070410780879",
"6157828888560609711850070085696122622",
"321829847506038911025978526598768705904",
"213470344503403687284382558590269688246",
"210941061041410051316720617124146933020",
"163039322464806677423007812268690881131",
"1093563972894592167501698070410780879",
"258063346411619122877021764642834582610",
"60279754391785713892671373811925391510",
"32473075544018111551695991140903872517",
"143574597959816610291178953448668655433",
"163039322464806677423007812268690881131",
"1093563972894592167501698070410780879",
"214416751302496696627460308722029490899",
"242597339247983714014903940000817059860",
"190963053462529804814939339526607193705",
"64099671290260447881390021967065001486",
"236944946890749384186104357007563837395",
"170258466125172096313911881221699592686",
"40207266930830163731345389386998665920",
"177224846745839383374672633956106749911",
"8812331577675612859517600085206227637",
"257603647200635393298886781752202101728",
"32911268485185499933978651879870148987",
"319351552339641412259325917916450132651",
"72335961729378066421880834554671919419",
"289485465976926062169099329600642797209",
"123305169719585538691303949866521541205",
"222949147706906562914537770572415937153",
"149341722020654154613754895660621759151",
"8783072397423199679793918816671605960",
"322582637801326483274126033248210946883",
"261758045718505884154933390197566919494",
"262621735965697647350607108360395634917",
"329662891966078498266911346043633354890",
"206011510499037192069096025622164914174",
"39509008995137443437522568118071707523",
"42812688004421362906821877865015077710"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://github.com/onlyoffice/core/commit/b17d5e860f30e8be2caeb0022b63be4c76660178",
"id": "CVE-2022-29777-99b6658a"
}
]