Search CVE reports


Toggle filters

21 – 30 of 110 results


CVE-2024-12426

Medium priority
Fixed

Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be constructed which expanded environmental variables or INI file values,...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice — Fixed Fixed Fixed —
Show less packages

CVE-2024-12425

Medium priority
Fixed

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice — Fixed Fixed Fixed —
Show less packages

CVE-2024-7788

Medium priority
Fixed

Improper Digital Signature InvalidationĀ  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 before < 24.2.5.

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice — Fixed Fixed Fixed —
Show less packages

CVE-2024-6472

Medium priority
Fixed

Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a signed macro...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice — Fixed Fixed Fixed —
Show less packages

CVE-0000-0003

High priority
Vulnerable

TEST CVE 3

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice — Vulnerable Vulnerable Not affected —
Show less packages

CVE-2024-5261

Medium priority
Fixed

Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is used by...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice — Fixed Not affected Not affected —
Show less packages

CVE-2024-3044

Medium priority
Fixed

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice — Fixed Fixed Fixed —
Show less packages

CVE-2023-36268

Low priority
Ignored

Rejected reason: DoS issues, or unexploitable crashes, are out of scope for vulnerabilities.

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice — Ignored Ignored Ignored —
Show less packages

CVE-2023-6186

Medium priority
Fixed

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice — — Fixed Fixed Ignored
Show less packages

CVE-2023-6185

Medium priority
Fixed

Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice — — Fixed Fixed Ignored
Show less packages