Перейти к содержимому
Noroxi

Записи libreoffice

71 опубликованных записей вендора libreoffice.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
3 · 4,2 %
Pre-auth RCE
17
С записью об исправлении
91,5 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

71 записей
  • CVE-2019-9851
    62На этой неделе

    LibreLogo global-event script execution

    КритическаяCVSS 9,8Готовый эксплойтEPSS 78 %

    libreoffice · libreoffice15 авг. 2019 г.

  • CVE-2018-16858
    59В плане

    It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute

    КритическаяCVSS 9,8Готовый эксплойтEPSS 67 %

    libreoffice · libreoffice25 мар. 2019 г.

  • CVE-2018-10583
    54В плане

    An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 78 %

    libreoffice · libreoffice1 мая 2018 г.

  • CVE-2019-9848
    48В плане

    LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-ov

    КритическаяCVSS 9,8Эксплойта нетEPSS 29 %

    libreoffice · libreoffice17 июл. 2019 г.

  • CVE-2018-6871
    46В плане

    LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use

    КритическаяCVSS 9,8Proof of conceptEPSS 23 %

    libreoffice · libreoffice9 февр. 2018 г.

  • CVE-2023-1183
    41В плане

    Arbitrary file write

    СредняяCVSS 5,5Эксплойта нетEPSS 65 %

    libreoffice · libreoffice10 июл. 2023 г.

  • CVE-2014-3524
    41В плане

    Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafte

    КритическаяCVSS 9,3Эксплойта нетEPSS 15 %

    apache · openoffice26 авг. 2014 г.

  • CVE-2014-0247
    41В плане

    LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/do

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    libreoffice · libreoffice3 июл. 2014 г.

  • CVE-2017-7870
    40В плане

    LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert functi

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    libreoffice · libreoffice14 апр. 2017 г.

  • CVE-2016-10327
    40В плане

    LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF func

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    libreoffice · libreoffice14 апр. 2017 г.

  • CVE-2017-7856
    40В плане

    LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 fun

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    libreoffice · libreoffice14 апр. 2017 г.

  • CVE-2019-9850
    40В плане

    Insufficient url validation allowing LibreLogo script execution

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    libreoffice · libreoffice15 авг. 2019 г.

  • CVE-2019-9855
    40В плане

    Windows 8.3 path equivalence handling flaw allows LibreLogo script execution

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    libreoffice · libreoffice6 сент. 2019 г.

  • CVE-2017-7882
    40В плане

    LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    libreoffice · libreoffice15 апр. 2017 г.

  • CVE-2018-14939
    40В плане

    The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environment

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    libreoffice · libreoffice5 авг. 2018 г.

  • CVE-2017-8358
    40В плане

    LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/sour

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    libreoffice · libreoffice30 апр. 2017 г.

  • CVE-2024-5261
    40В плане

    TLS certificate are not properly verified when utilizing LibreOfficeKit

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    libreoffice · libreoffice25 июн. 2024 г.

  • CVE-2011-2685
    39Наблюдать

    Stack-based buffer overflow in the Lotus Word Pro import filter in LibreOffice before 3.3.3 allows remote attackers to execute arbitrary cod

    КритическаяCVSS 9,3Эксплойта нетEPSS 7 %

    libreoffice · libreoffice21 июл. 2011 г.

  • CVE-2021-25631
    37Наблюдать

    denylist of executable filename extensions possible to bypass under windows

    ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %

    libreoffice · libreoffice3 мая 2021 г.

  • CVE-2022-26307
    35Наблюдать

    LibreOffice supports the storage of passwords for web connections in the user’s configuration database.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    libreoffice · libreoffice25 июл. 2022 г.

  • CVE-2023-6185
    35Наблюдать

    Improper input validation enabling arbitrary Gstreamer pipeline injection

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    libreoffice · libreoffice11 дек. 2023 г.

  • CVE-2023-6186
    35Наблюдать

    Link targets allow arbitrary script execution

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    libreoffice · libreoffice11 дек. 2023 г.

  • CVE-2012-1149
    34Наблюдать

    Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows r

    ВысокаяCVSS 7,5Эксплойта нетEPSS 14 %

    libreoffice · libreoffice21 июн. 2012 г.

  • CVE-2012-2665
    32Наблюдать

    Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5

    ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %

    libreoffice · libreoffice6 авг. 2012 г.

  • CVE-2014-3693
    32Наблюдать

    Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote at

    ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %

    libreoffice · libreoffice7 нояб. 2014 г.