Записи libreoffice
71 опубликованных записей вендора libreoffice.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 4,2 %
- Pre-auth RCE
- 17
- С записью об исправлении
- 91,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation10
- CWE-787 Out-of-bounds Write7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-295 Improper Certificate Validation6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-347 Improper Verification of Cryptographic Signature4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
71 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2019-9851Готовый эксплойт | LibreLogo global-event script executionlibreoffice · libreoffice · CWE-20 | Критическая9,8 | — | 77,8 % | 15 авг. 2019 г. |
59В плане | CVE-2018-16858Готовый эксплойт | It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute libreoffice · libreoffice · CWE-356 | Критическая9,8 | — | 67,3 % | 25 мар. 2019 г. |
54В плане | CVE-2018-10583Готовый эксплойт | An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate libreoffice · libreoffice · CWE-200 | Высокая7,5 | — | 78,3 % | 1 мая 2018 г. |
48В плане | CVE-2019-9848Эксплойта нет | LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-ovlibreoffice · libreoffice · CWE-94 | Критическая9,8 | — | 28,9 % | 17 июл. 2019 г. |
46В плане | CVE-2018-6871Proof of concept | LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which uselibreoffice · libreoffice | Критическая9,8 | — | 22,8 % | 9 февр. 2018 г. |
41В плане | CVE-2023-1183Эксплойта нет | Arbitrary file writelibreoffice · libreoffice · CWE-20 | Средняя5,5 | — | 64,6 % | 10 июл. 2023 г. |
41В плане | CVE-2014-3524Эксплойта нет | Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafteapache · openoffice · CWE-77 | Критическая9,3 | — | 14,5 % | 26 авг. 2014 г. |
41В плане | CVE-2014-0247Эксплойта нет | LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/dolibreoffice · libreoffice | Критическая10,0 | — | 3,9 % | 3 июл. 2014 г. |
40В плане | CVE-2017-7870Эксплойта нет | LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert functilibreoffice · libreoffice · CWE-787 | Критическая9,8 | — | 3,9 % | 14 апр. 2017 г. |
40В плане | CVE-2016-10327Эксплойта нет | LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF funclibreoffice · libreoffice · CWE-787 | Критическая9,8 | — | 3,6 % | 14 апр. 2017 г. |
40В плане | CVE-2017-7856Эксплойта нет | LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 funlibreoffice · libreoffice · CWE-787 | Критическая9,8 | — | 3,5 % | 14 апр. 2017 г. |
40В плане | CVE-2019-9850Эксплойта нет | Insufficient url validation allowing LibreLogo script executionlibreoffice · libreoffice · CWE-20 | Критическая9,8 | — | 2,9 % | 15 авг. 2019 г. |
40В плане | CVE-2019-9855Эксплойта нет | Windows 8.3 path equivalence handling flaw allows LibreLogo script executionlibreoffice · libreoffice · CWE-417 | Критическая9,8 | — | 2,6 % | 6 сент. 2019 г. |
40В плане | CVE-2017-7882Эксплойта нет | LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx.libreoffice · libreoffice · CWE-787 | Критическая9,8 | — | 2,4 % | 15 апр. 2017 г. |
40В плане | CVE-2018-14939Эксплойта нет | The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environmentlibreoffice · libreoffice · CWE-119 | Критическая9,8 | — | 2,2 % | 5 авг. 2018 г. |
40В плане | CVE-2017-8358Эксплойта нет | LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/sourlibreoffice · libreoffice · CWE-119 | Критическая9,8 | — | 2,1 % | 30 апр. 2017 г. |
40В плане | CVE-2024-5261Эксплойта нет | TLS certificate are not properly verified when utilizing LibreOfficeKitlibreoffice · libreoffice · CWE-295 | Критическая10,0 | — | 0,4 % | 25 июн. 2024 г. |
39Наблюдать | CVE-2011-2685Эксплойта нет | Stack-based buffer overflow in the Lotus Word Pro import filter in LibreOffice before 3.3.3 allows remote attackers to execute arbitrary codlibreoffice · libreoffice · CWE-119 | Критическая9,3 | — | 7,0 % | 21 июл. 2011 г. |
37Наблюдать | CVE-2021-25631Эксплойта нет | denylist of executable filename extensions possible to bypass under windowslibreoffice · libreoffice · CWE-184 | Высокая8,8 | — | 5,0 % | 3 мая 2021 г. |
35Наблюдать | CVE-2022-26307Эксплойта нет | LibreOffice supports the storage of passwords for web connections in the user’s configuration database.libreoffice · libreoffice · CWE-326 | Высокая8,8 | — | 1,4 % | 25 июл. 2022 г. |
35Наблюдать | CVE-2023-6185Эксплойта нет | Improper input validation enabling arbitrary Gstreamer pipeline injectionlibreoffice · libreoffice | Высокая8,8 | — | 1,0 % | 11 дек. 2023 г. |
35Наблюдать | CVE-2023-6186Эксплойта нет | Link targets allow arbitrary script executionlibreoffice · libreoffice · CWE-281 | Высокая8,8 | — | 0,8 % | 11 дек. 2023 г. |
34Наблюдать | CVE-2012-1149Эксплойта нет | Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows rlibreoffice · libreoffice · CWE-189 | Высокая7,5 | — | 14,2 % | 21 июн. 2012 г. |
32Наблюдать | CVE-2012-2665Эксплойта нет | Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5libreoffice · libreoffice · CWE-787 | Высокая7,5 | — | 7,0 % | 6 авг. 2012 г. |
32Наблюдать | CVE-2014-3693Эксплойта нет | Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote atlibreoffice · libreoffice | Высокая7,5 | — | 5,1 % | 7 нояб. 2014 г. |
- CVE-2019-985162На этой неделе
LibreLogo global-event script execution
КритическаяCVSS 9,8Готовый эксплойтEPSS 78 %libreoffice · libreoffice15 авг. 2019 г.
- CVE-2018-1685859В плане
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute
КритическаяCVSS 9,8Готовый эксплойтEPSS 67 %libreoffice · libreoffice25 мар. 2019 г.
- CVE-2018-1058354В плане
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate
ВысокаяCVSS 7,5Готовый эксплойтEPSS 78 %libreoffice · libreoffice1 мая 2018 г.
- CVE-2019-984848В плане
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-ov
КритическаяCVSS 9,8Эксплойта нетEPSS 29 %libreoffice · libreoffice17 июл. 2019 г.
- CVE-2018-687146В плане
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use
КритическаяCVSS 9,8Proof of conceptEPSS 23 %libreoffice · libreoffice9 февр. 2018 г.
- CVE-2023-118341В плане
Arbitrary file write
СредняяCVSS 5,5Эксплойта нетEPSS 65 %libreoffice · libreoffice10 июл. 2023 г.
- CVE-2014-352441В плане
Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafte
КритическаяCVSS 9,3Эксплойта нетEPSS 15 %apache · openoffice26 авг. 2014 г.
- CVE-2014-024741В плане
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/do
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %libreoffice · libreoffice3 июл. 2014 г.
- CVE-2017-787040В плане
LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert functi
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %libreoffice · libreoffice14 апр. 2017 г.
- CVE-2016-1032740В плане
LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF func
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %libreoffice · libreoffice14 апр. 2017 г.
- CVE-2017-785640В плане
LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 fun
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %libreoffice · libreoffice14 апр. 2017 г.
- CVE-2019-985040В плане
Insufficient url validation allowing LibreLogo script execution
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %libreoffice · libreoffice15 авг. 2019 г.
- CVE-2019-985540В плане
Windows 8.3 path equivalence handling flaw allows LibreLogo script execution
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %libreoffice · libreoffice6 сент. 2019 г.
- CVE-2017-788240В плане
LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %libreoffice · libreoffice15 апр. 2017 г.
- CVE-2018-1493940В плане
The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environment
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %libreoffice · libreoffice5 авг. 2018 г.
- CVE-2017-835840В плане
LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/sour
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %libreoffice · libreoffice30 апр. 2017 г.
- CVE-2024-526140В плане
TLS certificate are not properly verified when utilizing LibreOfficeKit
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %libreoffice · libreoffice25 июн. 2024 г.
- CVE-2011-268539Наблюдать
Stack-based buffer overflow in the Lotus Word Pro import filter in LibreOffice before 3.3.3 allows remote attackers to execute arbitrary cod
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %libreoffice · libreoffice21 июл. 2011 г.
- CVE-2021-2563137Наблюдать
denylist of executable filename extensions possible to bypass under windows
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %libreoffice · libreoffice3 мая 2021 г.
- CVE-2022-2630735Наблюдать
LibreOffice supports the storage of passwords for web connections in the user’s configuration database.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %libreoffice · libreoffice25 июл. 2022 г.
- CVE-2023-618535Наблюдать
Improper input validation enabling arbitrary Gstreamer pipeline injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %libreoffice · libreoffice11 дек. 2023 г.
- CVE-2023-618635Наблюдать
Link targets allow arbitrary script execution
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %libreoffice · libreoffice11 дек. 2023 г.
- CVE-2012-114934Наблюдать
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows r
ВысокаяCVSS 7,5Эксплойта нетEPSS 14 %libreoffice · libreoffice21 июн. 2012 г.
- CVE-2012-266532Наблюдать
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %libreoffice · libreoffice6 авг. 2012 г.
- CVE-2014-369332Наблюдать
Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote at
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %libreoffice · libreoffice7 нояб. 2014 г.