Show filters
60 Total Results
Displaying 31-40 of 60
Sort by:
Attacker Value
Unknown

CVE-2018-10583

Disclosure Date: May 01, 2018 (last updated November 08, 2023)
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.
0
Attacker Value
Unknown

CVE-2018-10120

Disclosure Date: April 16, 2018 (last updated November 08, 2023)
The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a customizations index, which allows remote attackers to cause a denial of service (heap-based buffer overflow with write access) or possibly have unspecified other impact via a crafted document that contains a certain Microsoft Word record.
0
Attacker Value
Unknown

CVE-2018-10119

Disclosure Date: April 16, 2018 (last updated November 08, 2023)
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format.
0
Attacker Value
Unknown

CVE-2018-6871

Disclosure Date: February 09, 2018 (last updated November 26, 2024)
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
0
Attacker Value
Unknown

CVE-2017-14226

Disclosure Date: September 09, 2017 (last updated November 26, 2024)
WP1StylesListener.cpp, WP5StylesListener.cpp, and WP42StylesListener.cpp in libwpd 0.10.1 mishandle iterators, which allows remote attackers to cause a denial of service (heap-based buffer over-read in the WPXTableList class in WPXTable.cpp). This vulnerability can be triggered in LibreOffice before 5.3.7. It may lead to suffering a remote attack against a LibreOffice application.
Attacker Value
Unknown

CVE-2017-8358

Disclosure Date: April 30, 2017 (last updated November 26, 2024)
LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/source/filter/jpeg/jpegc.cxx.
0
Attacker Value
Unknown

CVE-2017-7882

Disclosure Date: April 15, 2017 (last updated November 26, 2024)
LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx.
0
Attacker Value
Unknown

CVE-2016-10327

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF function in vcl/source/filter/wmf/enhwmf.cxx.
0
Attacker Value
Unknown

CVE-2017-7870

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function in tools/source/generic/poly.cxx.
0
Attacker Value
Unknown

CVE-2017-7856

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in vcl/source/gdi/svmconverter.cxx.
0