libreoffice kayıtları
libreoffice üreticisine ait 71 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %4,2
- Pre-auth RCE
- 17
- Düzeltme kaydı olan
- %91,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation10
- CWE-787 Out-of-bounds Write7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-295 Improper Certificate Validation6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-347 Improper Verification of Cryptographic Signature4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
71 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2019-9851Silahlaştırılmış | LibreLogo global-event script executionlibreoffice · libreoffice · CWE-20 | Kritik9,8 | — | %77,8 | 15 Ağu 2019 |
59Planlayın | CVE-2018-16858Silahlaştırılmış | It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute libreoffice · libreoffice · CWE-356 | Kritik9,8 | — | %67,3 | 25 Mar 2019 |
54Planlayın | CVE-2018-10583Silahlaştırılmış | An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate libreoffice · libreoffice · CWE-200 | Yüksek7,5 | — | %78,3 | 1 May 2018 |
48Planlayın | CVE-2019-9848İstismar yok | LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-ovlibreoffice · libreoffice · CWE-94 | Kritik9,8 | — | %28,9 | 17 Tem 2019 |
46Planlayın | CVE-2018-6871Kavram kanıtı | LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which uselibreoffice · libreoffice | Kritik9,8 | — | %22,8 | 9 Şub 2018 |
41Planlayın | CVE-2023-1183İstismar yok | Arbitrary file writelibreoffice · libreoffice · CWE-20 | Orta5,5 | — | %64,6 | 10 Tem 2023 |
41Planlayın | CVE-2014-3524İstismar yok | Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafteapache · openoffice · CWE-77 | Kritik9,3 | — | %14,5 | 26 Ağu 2014 |
41Planlayın | CVE-2014-0247İstismar yok | LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/dolibreoffice · libreoffice | Kritik10,0 | — | %3,9 | 3 Tem 2014 |
40Planlayın | CVE-2017-7870İstismar yok | LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert functilibreoffice · libreoffice · CWE-787 | Kritik9,8 | — | %3,9 | 14 Nis 2017 |
40Planlayın | CVE-2016-10327İstismar yok | LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF funclibreoffice · libreoffice · CWE-787 | Kritik9,8 | — | %3,6 | 14 Nis 2017 |
40Planlayın | CVE-2017-7856İstismar yok | LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 funlibreoffice · libreoffice · CWE-787 | Kritik9,8 | — | %3,5 | 14 Nis 2017 |
40Planlayın | CVE-2019-9850İstismar yok | Insufficient url validation allowing LibreLogo script executionlibreoffice · libreoffice · CWE-20 | Kritik9,8 | — | %2,9 | 15 Ağu 2019 |
40Planlayın | CVE-2019-9855İstismar yok | Windows 8.3 path equivalence handling flaw allows LibreLogo script executionlibreoffice · libreoffice · CWE-417 | Kritik9,8 | — | %2,6 | 6 Eyl 2019 |
40Planlayın | CVE-2017-7882İstismar yok | LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx.libreoffice · libreoffice · CWE-787 | Kritik9,8 | — | %2,4 | 15 Nis 2017 |
40Planlayın | CVE-2018-14939İstismar yok | The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environmentlibreoffice · libreoffice · CWE-119 | Kritik9,8 | — | %2,2 | 5 Ağu 2018 |
40Planlayın | CVE-2017-8358İstismar yok | LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/sourlibreoffice · libreoffice · CWE-119 | Kritik9,8 | — | %2,1 | 30 Nis 2017 |
40Planlayın | CVE-2024-5261İstismar yok | TLS certificate are not properly verified when utilizing LibreOfficeKitlibreoffice · libreoffice · CWE-295 | Kritik10,0 | — | %0,4 | 25 Haz 2024 |
39İzleyin | CVE-2011-2685İstismar yok | Stack-based buffer overflow in the Lotus Word Pro import filter in LibreOffice before 3.3.3 allows remote attackers to execute arbitrary codlibreoffice · libreoffice · CWE-119 | Kritik9,3 | — | %7,0 | 21 Tem 2011 |
37İzleyin | CVE-2021-25631İstismar yok | denylist of executable filename extensions possible to bypass under windowslibreoffice · libreoffice · CWE-184 | Yüksek8,8 | — | %5,0 | 3 May 2021 |
35İzleyin | CVE-2022-26307İstismar yok | LibreOffice supports the storage of passwords for web connections in the user’s configuration database.libreoffice · libreoffice · CWE-326 | Yüksek8,8 | — | %1,4 | 25 Tem 2022 |
35İzleyin | CVE-2023-6185İstismar yok | Improper input validation enabling arbitrary Gstreamer pipeline injectionlibreoffice · libreoffice | Yüksek8,8 | — | %1,0 | 11 Ara 2023 |
35İzleyin | CVE-2023-6186İstismar yok | Link targets allow arbitrary script executionlibreoffice · libreoffice · CWE-281 | Yüksek8,8 | — | %0,8 | 11 Ara 2023 |
34İzleyin | CVE-2012-1149İstismar yok | Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows rlibreoffice · libreoffice · CWE-189 | Yüksek7,5 | — | %14,2 | 21 Haz 2012 |
32İzleyin | CVE-2012-2665İstismar yok | Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5libreoffice · libreoffice · CWE-787 | Yüksek7,5 | — | %7,0 | 6 Ağu 2012 |
32İzleyin | CVE-2014-3693İstismar yok | Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote atlibreoffice · libreoffice | Yüksek7,5 | — | %5,1 | 7 Kas 2014 |
- CVE-2019-985162Bu hafta
LibreLogo global-event script execution
KritikCVSS 9,8SilahlaştırılmışEPSS %78libreoffice · libreoffice15 Ağu 2019
- CVE-2018-1685859Planlayın
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute
KritikCVSS 9,8SilahlaştırılmışEPSS %67libreoffice · libreoffice25 Mar 2019
- CVE-2018-1058354Planlayın
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate
YüksekCVSS 7,5SilahlaştırılmışEPSS %78libreoffice · libreoffice1 May 2018
- CVE-2019-984848Planlayın
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-ov
KritikCVSS 9,8İstismar yokEPSS %29libreoffice · libreoffice17 Tem 2019
- CVE-2018-687146Planlayın
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use
KritikCVSS 9,8Kavram kanıtıEPSS %23libreoffice · libreoffice9 Şub 2018
- CVE-2023-118341Planlayın
Arbitrary file write
OrtaCVSS 5,5İstismar yokEPSS %65libreoffice · libreoffice10 Tem 2023
- CVE-2014-352441Planlayın
Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafte
KritikCVSS 9,3İstismar yokEPSS %15apache · openoffice26 Ağu 2014
- CVE-2014-024741Planlayın
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/do
KritikCVSS 10,0İstismar yokEPSS %4libreoffice · libreoffice3 Tem 2014
- CVE-2017-787040Planlayın
LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert functi
KritikCVSS 9,8İstismar yokEPSS %4libreoffice · libreoffice14 Nis 2017
- CVE-2016-1032740Planlayın
LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF func
KritikCVSS 9,8İstismar yokEPSS %4libreoffice · libreoffice14 Nis 2017
- CVE-2017-785640Planlayın
LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 fun
KritikCVSS 9,8İstismar yokEPSS %3libreoffice · libreoffice14 Nis 2017
- CVE-2019-985040Planlayın
Insufficient url validation allowing LibreLogo script execution
KritikCVSS 9,8İstismar yokEPSS %3libreoffice · libreoffice15 Ağu 2019
- CVE-2019-985540Planlayın
Windows 8.3 path equivalence handling flaw allows LibreLogo script execution
KritikCVSS 9,8İstismar yokEPSS %3libreoffice · libreoffice6 Eyl 2019
- CVE-2017-788240Planlayın
LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx.
KritikCVSS 9,8İstismar yokEPSS %2libreoffice · libreoffice15 Nis 2017
- CVE-2018-1493940Planlayın
The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environment
KritikCVSS 9,8İstismar yokEPSS %2libreoffice · libreoffice5 Ağu 2018
- CVE-2017-835840Planlayın
LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/sour
KritikCVSS 9,8İstismar yokEPSS %2libreoffice · libreoffice30 Nis 2017
- CVE-2024-526140Planlayın
TLS certificate are not properly verified when utilizing LibreOfficeKit
KritikCVSS 10,0İstismar yokEPSS %0libreoffice · libreoffice25 Haz 2024
- CVE-2011-268539İzleyin
Stack-based buffer overflow in the Lotus Word Pro import filter in LibreOffice before 3.3.3 allows remote attackers to execute arbitrary cod
KritikCVSS 9,3İstismar yokEPSS %7libreoffice · libreoffice21 Tem 2011
- CVE-2021-2563137İzleyin
denylist of executable filename extensions possible to bypass under windows
YüksekCVSS 8,8İstismar yokEPSS %5libreoffice · libreoffice3 May 2021
- CVE-2022-2630735İzleyin
LibreOffice supports the storage of passwords for web connections in the user’s configuration database.
YüksekCVSS 8,8İstismar yokEPSS %1libreoffice · libreoffice25 Tem 2022
- CVE-2023-618535İzleyin
Improper input validation enabling arbitrary Gstreamer pipeline injection
YüksekCVSS 8,8İstismar yokEPSS %1libreoffice · libreoffice11 Ara 2023
- CVE-2023-618635İzleyin
Link targets allow arbitrary script execution
YüksekCVSS 8,8İstismar yokEPSS %1libreoffice · libreoffice11 Ara 2023
- CVE-2012-114934İzleyin
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows r
YüksekCVSS 7,5İstismar yokEPSS %14libreoffice · libreoffice21 Haz 2012
- CVE-2012-266532İzleyin
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5
YüksekCVSS 7,5İstismar yokEPSS %7libreoffice · libreoffice6 Ağu 2012
- CVE-2014-369332İzleyin
Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote at
YüksekCVSS 7,5İstismar yokEPSS %5libreoffice · libreoffice7 Kas 2014