CVE-2020-13958
- EPSS 2.9%
- Veröffentlicht 17.11.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:02:14
A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks pointing to an executable on the target users file system. These hyperlinks can be triggered unconditionally. In fixed versions no i...
CVE-2012-5639
- EPSS 5.84%
- Veröffentlicht 20.12.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 01:45:01
LibreOffice and OpenOffice automatically open embedded content
CVE-2011-2177
- EPSS 2%
- Veröffentlicht 27.11.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 01:27:45
OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.
CVE-2018-11790
- EPSS 1.03%
- Veröffentlicht 31.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:02
When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string length calculation.
CVE-2018-10583
- EPSS 78.97%
- Veröffentlicht 01.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:36
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg with...
CVE-2017-3157
- EPSS 3.12%
- Veröffentlicht 20.11.2017 20:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections...
CVE-2017-12608
- EPSS 2.89%
- Veröffentlicht 20.11.2017 20:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resu...
CVE-2017-12607
- EPSS 2.59%
- Veröffentlicht 20.11.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary c...
CVE-2017-9806
- EPSS 1.81%
- Veröffentlicht 20.11.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resu...
CVE-2016-6804
- EPSS 3.01%
- Veröffentlicht 20.11.2017 15:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that allows execution of arbitrary code with elevated privileges. This requires that the location in which ...