Search CVE reports


Toggle filters

1 – 10 of 91 results


CVE-2024-12426

Medium priority
Needs evaluation

Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be constructed which expanded environmental variables or INI file values,...

1 affected package

libreoffice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libreoffice Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-12425

Medium priority
Needs evaluation

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with...

1 affected package

libreoffice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libreoffice Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-7788

Medium priority
Fixed

Improper Digital Signature InvalidationĀ  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 before < 24.2.5.

1 affected package

libreoffice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libreoffice Fixed Fixed Fixed
Show less packages

CVE-2024-6472

Medium priority
Fixed

Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a signed macro...

1 affected package

libreoffice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libreoffice Fixed Fixed Fixed
Show less packages

CVE-0000-0003

High priority
Vulnerable

TEST CVE 3

1 affected package

libreoffice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libreoffice Vulnerable Vulnerable Not affected
Show less packages

CVE-2024-5261

Medium priority
Fixed

Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is used by...

1 affected package

libreoffice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libreoffice Fixed Not affected Not affected
Show less packages

CVE-2024-3044

Medium priority
Fixed

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts...

1 affected package

libreoffice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libreoffice Fixed Fixed Fixed
Show less packages

CVE-2023-36268

Low priority
Vulnerable

An issue in The Document Foundation Libreoffice v.7.4.7 allows a remote attacker to cause a denial of service via a crafted .ppt file.

1 affected package

libreoffice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libreoffice Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2023-6186

Medium priority
Fixed

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in...

1 affected package

libreoffice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libreoffice Fixed Fixed Ignored Ignored
Show less packages

CVE-2023-6185

Medium priority
Fixed

Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not...

1 affected package

libreoffice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libreoffice Fixed Fixed Ignored Ignored
Show less packages