FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-25 11:22:49 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
289269f1-0def-11e8-99b0-d017c2987f9aLibreOffice -- Remote arbitrary file disclosure vulnerability via WEBSERVICE formula

LibreOffice reports:

LibreOffice Calc supports a WEBSERVICE function to obtain data by URL. Vulnerable versions of LibreOffice allow WEBSERVICE to take a local file URL (e.g file://) which can be used to inject local files into the spreadsheet without warning the user. Subsequent formulas can operate on that inserted data and construct a remote URL whose path leaks the local data to a remote attacker.

In later versions of LibreOffice without this flaw, WEBSERVICE has now been limited to accessing http and https URLs along with bringing WEBSERVICE URLs under LibreOffice Calc's link management infrastructure.

Note: This vulnerability has been identified upstream as CVE-2018-1055, but NVD/Mitre are advising it's a reservation duplicate of CVE-2018-6871 which should be used instead.


Discovery 2018-02-09
Entry 2018-02-23
libreoffice
< 5.4.5

ge 6.0.0 lt 6.0.1

https://www.libreoffice.org/about-us/security/advisories/cve-2018-1055/
https://github.com/jollheef/libreoffice-remote-arbitrary-file-disclosure
CVE-2018-6871
ports/225797
3159cd70-4aaa-11e6-a7bd-14dae9d210b8libreoffice -- use-after-free vulnerability

Talos reports:

An exploitable Use After Free vulnerability exists in the RTF parser LibreOffice. A specially crafted file can cause a use after free resulting in a possible arbitrary code execution. To exploit the vulnerability a malicious file needs to be opened by the user via vulnerable application.


Discovery 2016-06-27
Entry 2016-07-15
libreoffice
< 5.1.4

http://www.talosintelligence.com/reports/TALOS-2016-0126/
http://www.libreoffice.org/about-us/security/advisories/cve-2016-4324/
CVE-2016-4324
96fb446d-ac7b-11ea-8b5e-b42e99a1b9c3LibreOffice Security Advisory

LibreOffice reports:

Two flaws were found in LibreOffice:

  • CVE-2020-12802: remote graphics contained in docx format retrieved in 'stealth mode'
  • CVE-2020-12803: XForms submissions could overwrite local files

Discovery 2020-06-08
Entry 2020-06-12
libreoffice
< 6.4.4

https://www.libreoffice.org/about-us/security/advisories/CVE-2020-12802
https://www.libreoffice.org/about-us/security/advisories/cve-2020-12803
CVE-2020-12802
CVE-2020-12803
b13af778-f4fc-11e4-a95d-ac9e174be3afVulnerability in HWP document filter

US-CERT/NIST reports:

The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.


Discovery 2015-04-27
Entry 2015-05-07
libreoffice
< 4.3.7

apache-openoffice
< 4.1.1_9

apache-openoffice-devel
< 4.2.1677190,3

CVE-2015-1774
http://www.openoffice.org/security/cves/CVE-2015-1774.html
https://www.libreoffice.org/about-us/security/advisories/cve-2015-1774/