Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Heap use-after-free in ODF number-format blank-width parsing
Vulnerability Description
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P
Vulnerability Type
释放后使用
Vulnerability Title
The Document Foundation LibreOffice 资源管理错误漏洞
Vulnerability Description
The Document Foundation LibreOffice是The Document Foundation的办公套件。 The Document Foundation LibreOffice存在安全漏洞,该漏洞源于在导入ODF数字格式的空格字符时存在堆释放后重用问题,未检查文件中读取的位置值是否超出格式码字符串长度,导致畸形数字格式可能处理字符串外部的内存。
CVSS Information
N/A
Vulnerability Type
N/A