« Volver al listado

Libreoffice

Libreoffice: vulnerabilidades y CVE

Libreoffice tiene 83 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 13 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE83
Últimos 12 meses13
Críticas13
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-63279Media (5.4)0.17%—22 sept 2026
LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being…
CVE-2026-63276Media (5.4)0.17%—22 sept 2026
LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The…
CVE-2026-63275Media (5.4)0.17%—22 sept 2026
LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more…
CVE-2026-63272Media (5.4)0.17%—22 sept 2026
LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the…
CVE-2026-55229Alta (7.5)1.5%—10 jul 2026
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpoint allows a specially crafted document to cause LibreOffice to automatically retrieve external…
CVE-2026-8356Media (5.4)0.17%—15 jun 2026
LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a colour-replacement record. Two fixed-size colour tables were filled from the file, but the write…
CVE-2026-6047Media (5.4)0.17%—15 jun 2026
LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at…
CVE-2026-6045Media (5.4)0.17%—15 jun 2026
LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to…
CVE-2026-6040Media (5.4)0.17%—15 jun 2026
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed…
CVE-2026-6039Media (5.4)0.17%—15 jun 2026
LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point count taken from the file was truncated to a 16-bit value when the point…
CVE-2026-4430Media (5.4)0.11%—7 may 2026
Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before…
CVE-2026-23623Media (5.3)0.24%—6 feb 2026
Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Development Edition version 25.04.08.2 and prior to Collabora Online versions 23.05.20.1, 24.04.17.3,…
CVE-2025-14714Baja (0.9)0.14%—15 dic 2025
An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application…
CVE-2025-2866Baja (2.4)0.12%—27 abr 2025
Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for…
CVE-2021-25635Media (5.2)0.14%—21 mar 2025
An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the target, then modify it to change the signature algorithm to an invalid…
CVE-2025-1080Alta (7.2)0.30%—4 mar 2025
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions…
CVE-2025-0514Alta (7.2)0.33%—25 feb 2025
Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditionally on activation.This issue affects LibreOffice: from 24.8 before <…
CVE-2024-12426Media (6.7)0.55%—7 ene 2025
Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be constructed which expanded environmental variables or INI…
CVE-2024-12425Baja (2.4)0.32%—7 ene 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit…
CVE-2024-7788Alta (7.8)0.20%—17 sept 2024
Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 before <…
CVE-2024-37311Alta (8.2)0.23%—23 ago 2024
Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remote host's…
CVE-2024-6472Alta (7.8)0.24%—5 ago 2024
Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a…
CVE-2024-5261Crítica (10)0.43%—25 jun 2024
Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this…
CVE-2024-3044Media (6.5)1.0%—14 may 2024
Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic.…
CVE-2023-6186Alta (8.8)0.77%—11 dic 2023
Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar…
CVE-2023-6185Alta (8.8)1.0%—11 dic 2023
Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video…
CVE-2023-1183Media (5.5)65%—10 jul 2023
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was…
CVE-2023-2255Media (5.3)2.2%—25 may 2023
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of…
CVE-2023-0950Alta (7.8)0.30%—25 may 2023
Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when…
CVE-2022-3140Media (6.3)5.7%—11 oct 2022
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution6
  2. T1059 Command and Scripting Interpreter4
  3. T1005 Data from Local System1
  4. T1059.007 JavaScript1
  5. T1090 Proxy1
  6. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Libreoffice