CVE-2022-26306
- EPSS 0.52%
- Veröffentlicht 25.07.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:53:43
LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization ...
CVE-2022-26305
- EPSS 0.62%
- Veröffentlicht 25.07.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:53:43
An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of the used certificate with that of a trusted certifica...
CVE-2021-25636
- EPSS 0.2%
- Veröffentlicht 24.02.2022 15:15:21
- Zuletzt bearbeitet 21.11.2024 05:55:11
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulner...
CVE-2021-25634
- EPSS 0.22%
- Veröffentlicht 12.10.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:11
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulner...
CVE-2021-25633
- EPSS 0.29%
- Veröffentlicht 11.10.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:11
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulner...
CVE-2021-25631
- EPSS 1.32%
- Veröffentlicht 03.05.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:10
In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an...
CVE-2018-18688
- EPSS 0%
- Veröffentlicht 07.01.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 03:56:22
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the...
CVE-2020-12803
- EPSS 1.17%
- Veröffentlicht 08.06.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:19
ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which...
CVE-2020-12802
- EPSS 0.47%
- Veröffentlicht 08.06.2020 16:15:09
- Zuletzt bearbeitet 21.11.2024 05:00:19
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include rem...
CVE-2020-12801
- EPSS 0.21%
- Veröffentlicht 18.05.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:19
If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If the recovery is successful, and if the file format...