Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libreoffice HIGH 7.8
CVE-2026-4430

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. Thi…

Fix: 25.8.7.0 / 26.2.3.0+
Fix from $1,950 2026-05-07
Libreoffice MEDIUM 6.5
CVE-2025-14714

An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Con…

Fix: 25.2.4.1+
Fix from $1,600 2025-12-15
Libreoffice MEDIUM 5.5
CVE-2025-2866

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affect…

Fix: 24.8.6.0 / 25.2.2+
Fix from $1,600 2025-04-27
Libreoffice MEDIUM 5.5
CVE-2021-25635

An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the…

Fix: 7.0.5.1+
Fix from $1,600 2025-03-21
Libreoffice HIGH 7.8
CVE-2025-0514

Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditio…

Fix: 24.8.5.1+
Fix from $1,950 2025-02-25
Libreoffice HIGH 7.8
CVE-2024-7788

Improper Digital Signature Invalidation  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerabili…

Fix: 24.2.5+
Fix from $1,950 2024-09-17
Libreoffice HIGH 7.8
CVE-2024-6472

Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by…

Fix: 24.2.5.1+
Fix from $1,950 2024-08-05
Libreoffice CRITICAL 9.8
CVE-2024-5261

Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be use…

Fix: 24.2.4+
Fix from $2,300 2024-06-25
Libreoffice HIGH 7.5
CVE-2022-26305

An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only …

Fix: 7.2.7 / 7.3.2+
Fix from $1,950 2022-07-25
Libreoffice HIGH 8.8
CVE-2021-25631EPSS 5%

In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manip…

Fix: 7.0.5 / 7.1.2+
Fix from $1,950 2021-05-03
Libreoffice MEDIUM 5.3
CVE-2020-12801

If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the docum…

Fix: 6.3.6 / 6.4.3+
Fix from $1,600 2020-05-18
Libreoffice HIGH 7.8
CVE-2019-9853

LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings, typically execution of macro…

Fix: 6.2.6 / 6.3.1+
Fix from $1,950 2019-09-27
Libreoffice CRITICAL 9.8
CVE-2019-9855

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained …

Fix: 6.2.7 / 6.3.1+
Fix from $2,300 2019-09-06
Libreoffice HIGH 7.8
CVE-2019-9847

A vulnerability in LibreOffice hyperlink processing allows an attacker to construct documents containing hyperlinks pointing to the location of an ex…

Fix: 6.1.6 / 6.2.3+
Fix from $1,950 2019-05-09
Libreoffice CRITICAL 9.8
CVE-2018-16858EPSS 67%

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary…

Fix: 6.0.7 / 6.1.3+
Fix from $2,300 2019-03-25
Libreoffice CRITICAL 9.8
CVE-2018-14939

The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environments such as…

Fix: after 6.0.5
Fix from $2,300 2018-08-05
Libreoffice HIGH 7.5
CVE-2017-14226

WP1StylesListener.cpp, WP5StylesListener.cpp, and WP42StylesListener.cpp in libwpd 0.10.1 mishandle iterators, which allows remote attackers to cause…

Fix: after 5.3.6
Fix from $1,950 2017-09-09
Libreoffice CRITICAL 9.8
CVE-2017-8358

LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/source/filter…

Fix: after 5.2.6
Fix from $2,300 2017-04-30
Libreoffice CRITICAL 9.8
CVE-2017-7882

LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx.

Fix: after 5.2.6
Fix from $2,300 2017-04-15
Libreoffice CRITICAL 9.8
CVE-2016-10327

LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF function in v…

Fix: after 5.3.0.0
Fix from $2,300 2017-04-14
Libreoffice CRITICAL 9.8
CVE-2017-7856

LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in …

Fix: after 5.2.6.1
Fix from $2,300 2017-04-14
Libreoffice CRITICAL 9.8
CVE-2017-7870

LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function in too…

Fix: after 5.3.0.0
Fix from $2,300 2017-04-14
Libreoffice HIGH 9.3
CVE-2011-2685EPSS 7%

Stack-based buffer overflow in the Lotus Word Pro import filter in LibreOffice before 3.3.3 allows remote attackers to execute arbitrary code via a c…

Fix: after 3.3.2
Fix from $1,950 2011-07-21