Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

96 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.6%—Libreoffice14/4/201717/6/2026
LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF function in vcl/source/filter/wmf/enhwmf.cxx.
ModificadaAlta (7.8)2.8%—Debian LinuxLibreofficeCanonical Ubuntu Linux8/7/201617/6/2026
Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted RTF file, related to stylesheet and superscript tokens.
ModificadaAlta (7.8)2.8%—LibreofficeCanonical Ubuntu Linux18/2/201617/6/2026
LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document.
ModificadaAlta (7.8)2.8%—LibreofficeCanonical Ubuntu Linux18/2/201617/6/2026
The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.
ModificadaMedia (6.8)9.6%—Canonical Ubuntu LinuxDebian LinuxLibreofficeApache Openoffice10/11/201517/6/2026
LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via an index to a non-existent bookmark in a DOC file.
ModificadaMedia (6.8)13%—Canonical Ubuntu LinuxDebian LinuxApache OpenofficeLibreoffice10/11/201517/6/2026
Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.
ModificadaMedia (6.8)8.7%—LibreofficeApache OpenofficeCanonical Ubuntu LinuxDebian Linux10/11/201517/6/2026
Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via crafted…
ModificadaMedia (4.3)14%—LibreofficeCanonical Ubuntu LinuxDebian LinuxApache Openoffice10/11/201517/6/2026
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1)…
ModificadaMedia (6.8)7.6%—Canonical Ubuntu LinuxDebian LinuxApache OpenofficeFedoraproject Fedora+428/4/201517/6/2026
The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.
ModificadaAlta (7.5)4.1%—LibreofficeFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux26/11/201417/6/2026
LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file.
ModificadaAlta (7.5)5.1%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationCanonical Ubuntu Linux+27/11/201417/6/2026
Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.
ModificadaMedia (4.3)11%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationApache Openoffice+127/8/201417/6/2026
The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects.
ModificadaAlta (9.3)15%—Apache OpenofficeLibreoffice26/8/201417/6/2026
Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.
ModificadaAlta (10)3.9%—Fedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+33/7/201417/6/2026
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
ModificadaMedia (4.3)3.5%—LibreofficeSUN Openoffice.org19/11/201216/6/2026
LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded…
ModificadaAlta (7.5)7.0%—Apache OpenofficeLibreofficeCanonical Ubuntu LinuxDebian Linux+76/8/201216/6/2026
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect…
ModificadaAlta (7.5)14%—LibreofficeDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+621/6/201216/6/2026
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC…
ModificadaMedia (6.8)13%—Apache Openoffice.orgLibreoffice19/6/201216/6/2026
Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the length of an Escher graphics record in a PowerPoint (.ppt)…
ModificadaMedia (6.5)14%—Librdf RaptorLibreofficeApache OpenofficeFedoraproject Fedora+917/6/201216/6/2026
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
ModificadaMedia (4.3)2.9%—LibreofficeSUN Openoffice.org21/10/201116/6/2026
oowriter in OpenOffice.org 3.3.0 and LibreOffice before 3.4.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers an out-of-bounds read in the DOC sprm parser.
ModificadaAlta (9.3)7.0%—Libreoffice21/7/201116/6/2026
Stack-based buffer overflow in the Lotus Word Pro import filter in LibreOffice before 3.3.3 allows remote attackers to execute arbitrary code via a crafted .lwp file.