cbcvebase.

Debian Libreoffice vulnerabilities

62 known vulnerabilities affecting debian/libreoffice.

Total CVEs
62
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH32MEDIUM13LOW9

Vulnerabilities

Page 1 of 4
CVE-2021-33035P2HIGHCVSS 7.8Exploitedfixed in libreoffice 1:4.3.1-1 (bookworm)2021
CVE-2021-33035 [HIGH] CVE-2021-33035: libreoffice - Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadshee... Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by alte
debian
CVE-2019-9851P2CRITICALCVSS 9.8PoCfixed in libreoffice 1:6.3.0-1 (bookworm)2019
CVE-2019-9851 [CRITICAL] CVE-2019-9851: libreoffice - LibreOffice is typically bundled with LibreLogo, a programmable turtle vector gr... LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from document event script handers, e.g. mouse over. However LibreOffice also has a separate featur
debian
CVE-2018-16858P1HIGHCVSS 7.8PoCfixed in libreoffice 1:6.1.3-1 (bookworm)2018
CVE-2018-16858 [HIGH] CVE-2018-16858: libreoffice - It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to ... It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the Lib
debian
CVE-2019-9848P2CRITICALCVSS 9.8PoCfixed in libreoffice 1:6.3.0~rc1-1 (bookworm)2019
CVE-2019-9848 [CRITICAL] CVE-2019-9848: libreoffice - LibreOffice has a feature where documents can specify that pre-installed scripts... LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands. By using the document event feature to trigger
debian
CVE-2018-6871P2CRITICALCVSS 9.8PoCfixed in libreoffice 1:6.0.1-1 (bookworm)2018
CVE-2018-6871 [CRITICAL] CVE-2018-6871: libreoffice - LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read ar... LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function. Scope: local bookworm: resolved (fixed in 1:6.0.1-1) bullseye: resolved (fixed in 1:6.0.1-1) forky: resolved (fixed in 1:6.0.1-1) sid: resolved (fixed in 1:6.0.1-1) trixie: resolved
debian
CVE-2019-9850P3CRITICALCVSS 9.8fixed in libreoffice 1:6.3.0-1 (bookworm)2019
CVE-2019-9850 [CRITICAL] CVE-2019-9850: libreoffice - LibreOffice is typically bundled with LibreLogo, a programmable turtle vector gr... LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script events such as mouse-over, etc. Protection wa
debian
CVE-2023-6185P3HIGHCVSS 8.3fixed in libreoffice 4:7.4.7-1+deb12u1 (bookworm)2023
CVE-2023-6185 [HIGH] CVE-2023-6185: libreoffice - Improper Input Validation vulnerability in GStreamer integration of The Document... Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installe
debian
CVE-2022-26307P3HIGHCVSS 8.8fixed in libreoffice 1:7.3.3~rc1-2 (bookworm)2022
CVE-2022-26307 [HIGH] CVE-2022-26307: libreoffice - LibreOffice supports the storage of passwords for web connections in the user’s ... LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulerable to a brute force at
debian
CVE-2024-5261P3LOWCVSS 10.0fixed in libreoffice 4:24.2.4-1 (forky)2024
CVE-2024-5261 [CRITICAL] CVE-2024-5261: libreoffice - Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mo... Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is used by third party components to reuse LibreOffice as a library to convert, view or otherwise interact with documents. LibreOffice interna
debian
CVE-2023-6186P3HIGHCVSS 8.3fixed in libreoffice 4:7.4.7-1+deb12u1 (bookworm)2023
CVE-2023-6186 [HIGH] CVE-2023-6186: libreoffice - Insufficient macro permission validation of The Document Foundation LibreOffice ... Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user. Scope: local bookworm: resolved (fixed in 4:7.4.7-1+deb12u1)
debian
CVE-2017-7870P3CRITICALCVSS 9.8fixed in libreoffice 1:5.2.5-1 (bookworm)2017
CVE-2017-7870 [CRITICAL] CVE-2017-7870: libreoffice - LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based ... LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function in tools/source/generic/poly.cxx. Scope: local bookworm: resolved (fixed in 1:5.2.5-1) bullseye: resolved (fixed in 1:5.2.5-1) forky: resolved (fixed in 1:5.2.5-1) sid: resolved (fixed in 1:5.2.5-1) trixie: resolved (fi
debian
CVE-2016-10327P3CRITICALCVSS 9.8fixed in libreoffice 1:5.2.5-1 (bookworm)2016
CVE-2016-10327 [CRITICAL] CVE-2016-10327: libreoffice - LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based ... LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF function in vcl/source/filter/wmf/enhwmf.cxx. Scope: local bookworm: resolved (fixed in 1:5.2.5-1) bullseye: resolved (fixed in 1:5.2.5-1) forky: resolved (fixed in 1:5.2.5-1) sid: resolved (fixed in 1:5.2.5-1) trixie: resol
debian
CVE-2011-2685P3CRITICALCVSS 9.3fixed in libreoffice 1:3.3.3-1 (bookworm)2011
CVE-2011-2685 [CRITICAL] CVE-2011-2685: libreoffice - Stack-based buffer overflow in the Lotus Word Pro import filter in LibreOffice b... Stack-based buffer overflow in the Lotus Word Pro import filter in LibreOffice before 3.3.3 allows remote attackers to execute arbitrary code via a crafted .lwp file. Scope: local bookworm: resolved (fixed in 1:3.3.3-1) bullseye: resolved (fixed in 1:3.3.3-1) forky: resolved (fixed in 1:3.3.3-1) sid: resolved (fixed in 1:3.3.3-1) trixie: resolved (fixed in 1:3
debian
CVE-2012-1149P3HIGHCVSS 7.5fixed in libreoffice 1:3.4.5-1 (bookworm)2012
CVE-2012-1149 [HIGH] CVE-2012-1149: libreoffice - Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, ... Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overf
debian
CVE-2022-26306P3HIGHCVSS 7.5fixed in libreoffice 1:7.3.3~rc1-2 (bookworm)2022
CVE-2022-26306 [HIGH] CVE-2022-26306: libreoffice - LibreOffice supports the storage of passwords for web connections in the user’s ... LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if a
debian
CVE-2014-3693P3HIGHCVSS 7.5fixed in libreoffice 1:4.3.3~rc2~git20141011-1 (bookworm)2014
CVE-2014-3693 [HIGH] CVE-2014-3693: libreoffice - Use-after-free vulnerability in the socket manager of Impress Remote in LibreOff... Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599. Scope: local bookworm: resolved (fixed in 1:4.3.3~rc2~git20141011-1) bullseye: resolved (fixed in 1:4.3.3~
debian
CVE-2019-9853P3HIGHCVSS 7.8fixed in libreoffice 1:6.3.0-1 (bookworm)2019
CVE-2019-9853 [HIGH] CVE-2019-9853: libreoffice - LibreOffice documents can contain macros. The execution of those macros is contr... LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings, typically execution of macros are blocked by default. A URL decoding flaw existed in how the urls to the macros within the document were processed and categorized, resulting in the possibility to construct a document where macro execution bypass
debian
CVE-2012-2665P3HIGHCVSS 7.5fixed in libreoffice 1:3.5.4-7 (bookworm)2012
CVE-2012-2665 [HIGH] CVE-2012-2665: libreoffice - Multiple heap-based buffer overflows in the XML manifest encryption tag parsing ... Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 Che
debian
CVE-2022-26305P3HIGHCVSS 7.5fixed in libreoffice 1:7.3.2~rc2-1 (bookworm)2022
CVE-2022-26305 [HIGH] CVE-2022-26305: libreoffice - An Improper Certificate Validation vulnerability in LibreOffice existed where de... An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of the used certificate with that of a trusted certificate. This is not sufficient to verify that the macro was actually signed with the certificate. An adversary could t
debian
CVE-2021-25636P3HIGHCVSS 7.5fixed in libreoffice 1:7.3.0-1 (bookworm)2021
CVE-2021-25636 [HIGH] CVE-2021-25636: libreoffice - LibreOffice supports digital signatures of ODF documents and macros within docum... LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the document
debian
Debian Libreoffice vulnerabilities | cvebase