Libreoffice

Libreoffice

69 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.76%
  • Veröffentlicht 06.09.2019 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Script...

  • EPSS 2.91%
  • Veröffentlicht 15.08.2019 22:15:22
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify tha...

  • EPSS 85.78%
  • Veröffentlicht 15.08.2019 22:15:22
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calli...

  • EPSS 0.11%
  • Veröffentlicht 15.08.2019 22:15:22
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Script...

  • EPSS 3.56%
  • Veröffentlicht 17.07.2019 12:15:10
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include rem...

  • EPSS 86.56%
  • Veröffentlicht 17.07.2019 12:15:10
  • Zuletzt bearbeitet 21.11.2024 04:52:25

LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, w...

  • EPSS 0.24%
  • Veröffentlicht 09.05.2019 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:25

A vulnerability in LibreOffice hyperlink processing allows an attacker to construct documents containing hyperlinks pointing to the location of an executable on the target users file system. If the hyperlink is activated by the victim the executable ...

Exploit
  • EPSS 92.34%
  • Veröffentlicht 25.03.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:27

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice...

  • EPSS 0.53%
  • Veröffentlicht 05.08.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:50:07

The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environments such as FreeBSD libc, which might allow attackers to cause a denial of service (buffer overflow and applicat...

Exploit
  • EPSS 71.9%
  • Veröffentlicht 01.05.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:36

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg with...