Antennahouse develops document conversion and rendering software, particularly tools that transform office formats and PDFs for server-side processing, which places its products in the data-transformation pipeline of many enterprise environments. The vendor's vulnerabilities cluster in its core converters and concentrate around memory-safety issues such as out-of-bounds writes and heap-based buffer overflows, alongside XML external entity handling flaws that are characteristic of format-parsing attack surfaces. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Antennahouse over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5030HIGH A buffer overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0 Pro MR1 (7,0,2019,0220). While parsing a | Oct 31, 2019 | 8.8 | 27 | NO | NO |
CVE-2021-20838HIGH Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a deni | Nov 1, 2021 | 7.5 | 25 | NO | NO |
CVE-2018-3936HIGH In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resu | Jul 11, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-3932HIGH An exploitable stack-based buffer overflow exists in the Microsoft Word document conversion functionality of the Antenna House Office Server Document Converter version V6.1 Pro MR2 | Jul 11, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-3931HIGH In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resu | Jul 11, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-3930HIGH In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resu | Jul 11, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-3929HIGH An exploitable heap corruption exists in the PowerPoint document conversion functionality of the Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6, | Jul 11, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-3933HIGH An exploitable out-of-bounds write exists in the Microsoft Word document conversion functionality of the Antenna House Office Server Document Converter version V6.1 Pro MR2 for Lin | Jul 11, 2018 | 7.8 | 24 | NO | NO |
CVE-2021-20839MEDIUM Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a deni | Nov 1, 2021 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Antennahouse.
Media articles that mention a CVE ID that affects a product developed by Antennahouse — matched by CVE ID, not by vendor name.