Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 3.5% | — | LibreofficeSUN Openoffice.org | 19/11/2012 | 16/6/2026 | LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded… | |
| Modificada | Alta (7.5) | 14% | — | Redhat Enterprise Linux Optional Productivity ApplicationsRedhat Enterprise Linux DesktopApache Openoffice.orgLibwpd | 21/6/2012 | 16/6/2026 | The WPXContentListener::_closeTableRow function in WPXContentListener.cpp in libwpd 0.8.8, as used by OpenOffice.org (OOo) before 3.4, allows remote attackers to execute arbitrary code via a crafted Wordperfect .WPD document that causes a negative array index to be used. NOTE: some sources report this issue as an… | |
| Modificada | Alta (7.5) | 14% | — | LibreofficeDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+6 | 21/6/2012 | 16/6/2026 | Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC… | |
| Modificada | Media (6.8) | 13% | — | Apache Openoffice.orgLibreoffice | 19/6/2012 | 16/6/2026 | Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the length of an Escher graphics record in a PowerPoint (.ppt)… | |
| Modificada | Media (4.3) | 2.9% | — | LibreofficeSUN Openoffice.org | 21/10/2011 | 16/6/2026 | oowriter in OpenOffice.org 3.3.0 and LibreOffice before 3.4.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers an out-of-bounds read in the DOC sprm parser. | |
| Modificada | Alta (9.3) | 7.1% | — | Openoffice.org | 25/8/2010 | 16/6/2026 | Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 7.1% | — | Openoffice.org | 25/8/2010 | 16/6/2026 | simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that… | |
| Modificada | Alta (9.3) | 1.3% | — | Openoffice.org | 6/10/2009 | 16/6/2026 | Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side exploit." NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a… | |
| Modificada | Alta (10) | 1.5% | — | Openoffice.org | 6/10/2009 | 16/6/2026 | Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9. NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue… | |
| Modificada | Alta (9.3) | 9.8% | — | Apache Openoffice.org | 6/10/2009 | 16/6/2026 | Stack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side stack overflow exploit." NOTE: as of 20091005, this disclosure has no actionable information. However,… | |
| Modificada | Alta (9.3) | 6.5% | — | SUN Openoffice.org | 8/9/2009 | 16/6/2026 | Heap-based buffer overflow in svtools/source/filter.vcl/wmf/enhwmf.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allows remote attackers to execute arbitrary code via a crafted EMF file, a similar issue to CVE-2008-2238. | |
| Modificada | Alta (9.3) | 6.7% | — | Openoffice.org | 2/9/2009 | 16/6/2026 | Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to "table parsing." | |
| Modificada | Alta (9.3) | 6.7% | — | Openoffice.org | 2/9/2009 | 16/6/2026 | Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 1.8% | — | Xmlsoft LibxmlXmlsoft Libxml2Fedoraproject FedoraDebian Linux+15 | 11/8/2009 | 16/6/2026 | Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing… | |
| Modificada | Alta (9.3) | 7.5% | — | Openoffice.org | 22/1/2009 | 16/6/2026 | The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by… | |
| Modificada | Baja (2.6) | 0.45% | — | Openoffice.org | 5/11/2008 | 16/6/2026 | senddoc in OpenOffice.org (OOo) 2.4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/log.obr.##### temporary file. | |
| Modificada | Alta (9.3) | 6.7% | — | Openoffice.org | 30/10/2008 | 16/6/2026 | Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 6.1% | — | Openoffice.org | 30/10/2008 | 16/6/2026 | Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associated with a StarOffice/StarSuite document. | |
| Modificada | Alta (7.5) | 1.9% | — | Openoffice.org | 1/8/2008 | 16/6/2026 | OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |
| Modificada | Alta (9.3) | 5.7% | — | Openoffice.org | 10/6/2008 | 16/6/2026 | Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 4.1% | — | SUN Openoffice.org | 17/4/2008 | 16/6/2026 | Integer underflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted values that trigger an excessive loop and a stack-based buffer overflow. | |
| Modificada | Media (6.8) | 4.6% | — | Openoffice.org | 17/4/2008 | 16/6/2026 | Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an EMF file with a crafted EMR_STRETCHBLT record, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 57% | — | Openoffice.org | 17/4/2008 | 16/6/2026 | Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream. |