The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Computer vulnerabilities of LibreOffice

computer vulnerability CVE-2019-9849

LibreOffice: information disclosure via Stealth Mode Bullet Graphics

Synthesis of the vulnerability

An attacker can bypass access restrictions to data via Stealth Mode Bullet Graphics of LibreOffice, in order to obtain sensitive information.
Severity: 2/4.
Creation date: 17/07/2019.
Identifiers: CVE-2019-9849, DLA-1947-1, DSA-4483-1, openSUSE-SU-2019:2057-1, openSUSE-SU-2019:2183-1, SUSE-SU-2019:2231-1, SUSE-SU-2019:2401-1, SUSE-SU-2019:2402-1, USN-4063-1, VIGILANCE-VUL-29799.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can bypass access restrictions to data via Stealth Mode Bullet Graphics of LibreOffice, in order to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

cybersecurity announce CVE-2019-9847

LibreOffice: code execution via an hypertext link

Synthesis of the vulnerability

An attacker can use a vulnerability in the handling of hypertext links in LibreOffice, in order to run an external program.
Severity: 2/4.
Creation date: 09/05/2019.
Identifiers: CVE-2019-9847, VIGILANCE-VUL-29258.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can use a vulnerability in the handling of hypertext links in LibreOffice, in order to run an external program.
Full Vigil@nce bulletin... (Free trial)

vulnerability alert CVE-2018-16858

LibreOffice/OpenOffice: code execution via Macro/Event Script Event-listener

Synthesis of the vulnerability

An attacker can use a vulnerability via Macro/Event Script Event-listener of LibreOffice/OpenOffice, in order to run code.
Severity: 3/4.
Creation date: 04/02/2019.
Identifiers: CERTFR-2019-AVI-047, CVE-2018-16858, DLA-1669-1, DSA-4381-1, openSUSE-SU-2019:1929-1, RHSA-2019:2130-01, SUSE-SU-2019:1894-1, USN-3883-1, VIGILANCE-VUL-28427.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can use a vulnerability via Macro/Event Script Event-listener of LibreOffice/OpenOffice, in order to run code.
Full Vigil@nce bulletin... (Free trial)

threat bulletin CVE-2018-14939

LibreOffice: buffer overflow via FreeBSD realpath

Synthesis of the vulnerability

An attacker can generate a buffer overflow via FreeBSD realpath() of LibreOffice, in order to trigger a denial of service, and possibly to run code.
Severity: 2/4.
Creation date: 06/08/2018.
Identifiers: 118514, CVE-2018-14939, VIGILANCE-VUL-26911.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can generate a buffer overflow via FreeBSD realpath() of LibreOffice, in order to trigger a denial of service, and possibly to run code.
Full Vigil@nce bulletin... (Free trial)

weakness CVE-2018-10583

LibreOffice/OpenOffice: information disclosure via SMB Credentials

Synthesis of the vulnerability

An attacker can bypass access restrictions to data via SMB Credential of LibreOffice/OpenOffice, in order to obtain sensitive information.
Severity: 2/4.
Creation date: 02/05/2018.
Identifiers: CVE-2018-10583, openSUSE-SU-2018:2532-1, openSUSE-SU-2018:2533-1, openSUSE-SU-2018:3796-1, RHSA-2018:3054-01, SUSE-SU-2018:2485-1, SUSE-SU-2018:2485-2, SUSE-SU-2018:2535-1, SUSE-SU-2018:3683-1, USN-3883-1, VIGILANCE-VUL-26023.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can bypass access restrictions to data via SMB Credential of LibreOffice/OpenOffice, in order to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

weakness note CVE-2018-10120

LibreOffice: buffer overflow via SwCTBWrapper-Read

Synthesis of the vulnerability

An attacker can generate a buffer overflow via SwCTBWrapper::Read() of LibreOffice, in order to trigger a denial of service, and possibly to run code.
Severity: 2/4.
Creation date: 16/04/2018.
Identifiers: CVE-2018-10120, DLA-1356-1, DSA-4178-1, openSUSE-SU-2018:1311-1, RHSA-2018:3054-01, SUSE-SU-2018:1296-1, USN-3883-1, VIGILANCE-VUL-25881.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can generate a buffer overflow via SwCTBWrapper::Read() of LibreOffice, in order to trigger a denial of service, and possibly to run code.
Full Vigil@nce bulletin... (Free trial)

computer threat announce CVE-2018-10119

LibreOffice: use after free via StgSmallStrm

Synthesis of the vulnerability

An attacker can force the usage of a freed memory area via StgSmallStrm of LibreOffice, in order to trigger a denial of service, and possibly to run code.
Severity: 2/4.
Creation date: 16/04/2018.
Identifiers: CVE-2018-10119, DLA-1356-1, DSA-4178-1, openSUSE-SU-2018:1311-1, RHSA-2018:3054-01, SUSE-SU-2018:1296-1, USN-3883-1, VIGILANCE-VUL-25880.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can force the usage of a freed memory area via StgSmallStrm of LibreOffice, in order to trigger a denial of service, and possibly to run code.
Full Vigil@nce bulletin... (Free trial)

weakness CVE-2018-6871

LibreOffice: directory traversal

Synthesis of the vulnerability

An attacker can traverse directories of LibreOffice, in order to read a file outside the service root path.
Severity: 2/4.
Number of vulnerabilities in this bulletin: 2.
Creation date: 12/02/2018.
Identifiers: CVE-2018-1055-REJECT, CVE-2018-6871, DSA-4111-1, DSA-4111-2, FEDORA-2018-0a3b07a003, FEDORA-2018-3eb4d8e4c4, openSUSE-SU-2018:0446-1, RHSA-2018:0418-01, RHSA-2018:0517-01, SUSE-SU-2018:0428-1, USN-3579-1, USN-3579-2, USN-3579-3, VIGILANCE-VUL-25275.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can traverse directories of LibreOffice, in order to read a file outside the service root path.
Full Vigil@nce bulletin... (Free trial)

computer weakness note CVE-2017-14226

libwpd: out-of-bounds memory reading via WPXTableList

Synthesis of the vulnerability

An attacker can force a read at an invalid address via WPXTableList of libwpd, in order to trigger a denial of service, or to obtain sensitive information.
Severity: 2/4.
Creation date: 11/09/2017.
Identifiers: 112269, CVE-2017-14226, FEDORA-2017-63ff51c0dc, FEDORA-2017-6e66393536, openSUSE-SU-2017:2943-1, SUSE-SU-2017:2931-1, VIGILANCE-VUL-23796.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can force a read at an invalid address via WPXTableList of libwpd, in order to trigger a denial of service, or to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

cybersecurity announce CVE-2017-8358

LibreOffice: memory corruption via ReadJPEG

Synthesis of the vulnerability

An attacker can generate a memory corruption via ReadJPEG() of LibreOffice, in order to trigger a denial of service, and possibly to run code.
Severity: 2/4.
Creation date: 02/05/2017.
Identifiers: CVE-2017-8358, openSUSE-SU-2017:1851-1, openSUSE-SU-2017:2488-1, VIGILANCE-VUL-22614.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can generate a memory corruption via ReadJPEG() of LibreOffice, in order to trigger a denial of service, and possibly to run code.
Full Vigil@nce bulletin... (Free trial)
Our database contains other pages. You can request a free trial to read them.

Display information about LibreOffice: