Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.9) | 0.65% | — | Apache OpenofficeCanonical Ubuntu LinuxDebian Linux | 28/1/2011 | 16/6/2026 | soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | |
| Modificada | Alta (9.3) | 10% | — | Apache OpenofficeCanonical Ubuntu LinuxDebian Linux | 28/1/2011 | 16/6/2026 | Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers… | |
| Modificada | Alta (9.3) | 9.7% | — | Apache OpenofficeCanonical Ubuntu LinuxDebian Linux | 28/1/2011 | 16/6/2026 | The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or… | |
| Modificada | Alta (9.3) | 10% | — | Apache OpenofficeCanonical Ubuntu LinuxDebian Linux | 28/1/2011 | 16/6/2026 | Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document. | |
| Modificada | Alta (9.3) | 10% | — | Apache OpenofficeCanonical Ubuntu LinuxDebian Linux | 28/1/2011 | 16/6/2026 | Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via malformed tables in an RTF document. | |
| Modificada | Alta (9.3) | 11% | — | Apache OpenofficeCanonical Ubuntu LinuxDebian Linux | 28/1/2011 | 16/6/2026 | Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filter description file, (2) an Extension (aka OXT) file, or unspecified other (3) JAR or (4) ZIP files. | |
| Modificada | Alta (7.5) | 5.9% | — | Google ChromeXmlsoft Libxml2Apple ItunesApple Safari+13 | 7/12/2010 | 16/6/2026 | Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling. | |
| Modificada | Media (4.3) | 2.7% | — | Google ChromeApple ItunesApple SafariApple Iphone OS+11 | 17/11/2010 | 16/6/2026 | libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML… | |
| Modificada | Alta (9.3) | 7.1% | — | Openoffice.org | 25/8/2010 | 16/6/2026 | Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 7.1% | — | Openoffice.org | 25/8/2010 | 16/6/2026 | simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that… | |
| Modificada | Alta (9.3) | 10% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraOpensuse+2 | 10/6/2010 | 16/6/2026 | OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed. | |
| Modificada | Alta (9.3) | 8.1% | — | Apache OpenofficeCanonical Ubuntu LinuxDebian Linux | 16/2/2010 | 16/6/2026 | OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document. | |
| Modificada | Alta (9.3) | 12% | — | Apache OpenofficeCanonical Ubuntu LinuxDebian Linux | 16/2/2010 | 16/6/2026 | filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTSetBrc table property modifier in a Word document, related to a "boundary error flaw." | |
| Modificada | Alta (9.3) | 12% | — | Apache OpenofficeCanonical Ubuntu LinuxDebian Linux | 16/2/2010 | 16/6/2026 | Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document. | |
| Modificada | Alta (9.3) | 14% | — | Apache OpenofficeCanonical Ubuntu LinuxDebian Linux | 16/2/2010 | 16/6/2026 | Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression. | |
| Modificada | Alta (9.3) | 14% | — | Apache OpenofficeCanonical Ubuntu LinuxDebian Linux | 16/2/2010 | 16/6/2026 | Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 1.3% | — | Openoffice.org | 6/10/2009 | 16/6/2026 | Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side exploit." NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a… | |
| Modificada | Alta (10) | 1.5% | — | Openoffice.org | 6/10/2009 | 16/6/2026 | Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9. NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue… | |
| Modificada | Alta (9.3) | 9.8% | — | Apache Openoffice.org | 6/10/2009 | 16/6/2026 | Stack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side stack overflow exploit." NOTE: as of 20091005, this disclosure has no actionable information. However,… | |
| Modificada | Alta (9.3) | 6.5% | — | SUN Openoffice.org | 8/9/2009 | 16/6/2026 | Heap-based buffer overflow in svtools/source/filter.vcl/wmf/enhwmf.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allows remote attackers to execute arbitrary code via a crafted EMF file, a similar issue to CVE-2008-2238. | |
| Modificada | Alta (9.3) | 6.7% | — | Openoffice.org | 2/9/2009 | 16/6/2026 | Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to "table parsing." | |
| Modificada | Alta (9.3) | 6.7% | — | Openoffice.org | 2/9/2009 | 16/6/2026 | Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 1.8% | — | Xmlsoft LibxmlXmlsoft Libxml2Fedoraproject FedoraDebian Linux+15 | 11/8/2009 | 16/6/2026 | Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing… | |
| Modificada | Alta (9.3) | 7.5% | 💥 Exploit | Openoffice.org | 22/1/2009 | 16/6/2026 | The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by… | |
| Modificada | Baja (2.6) | 0.45% | — | Openoffice.org | 5/11/2008 | 16/6/2026 | senddoc in OpenOffice.org (OOo) 2.4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/log.obr.##### temporary file. |