目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

The Document Foundation 厂商漏洞列表 / CVE 中文分析 34

The Document Foundation 厂商相关 34 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

The Document Foundation 致力于开发 LibreOffice 等开源办公套件,核心用途为提供跨平台的文档处理解决方案。其历史漏洞多集中于文档解析环节,常见类型包括远程代码执行、内存破坏及拒绝服务攻击,部分案例涉及越权访问。值得关注的是,该组织对安全响应较为积极,定期发布补丁修复高危缺陷,并建立了明确的漏洞披露流程,以保障用户数据在处理复杂格式文件时的安全性与稳定性。

上位製品 The Document Foundation: LibreOffice
CVE IDタイトルCVSS深刻度公開日
CVE-2026-8358 Heap buffer overflow in spreadsheet tracked-changes import — LibreOfficeCWE-843--2026-06-15
CVE-2026-8357 Heap buffer overflow in Calc formula compilation — LibreOfficeCWE-787 5.4 Medium2026-06-15
CVE-2026-8356 Stack buffer overflow in PPT presentation import — LibreOfficeCWE-787--2026-06-15
CVE-2026-6047 Heap buffer overflow in OOXML text box element import — LibreOfficeCWE-787--2026-06-15
CVE-2026-6045 Heap buffer overflow in EMF+ gradient brush import — LibreOfficeCWE-787--2026-06-15
CVE-2026-6040 Heap use-after-free in ODF number-format blank-width parsing — LibreOfficeCWE-416 5.4 Medium2026-06-15
CVE-2026-6039 Heap buffer overflow in DXF polyline import — LibreOfficeCWE-787--2026-06-15
CVE-2026-4430 Heap Buffer Overflow in AgileEngine — LibreOfficeCWE-787 7.8AIHighAI2026-05-07
CVE-2025-14714 TCC Bypass via Inherited Permissions in Bundled Interpreter — LibreOfficeCWE-288 9.8AICriticalAI2025-12-15
CVE-2025-2866 PDF signature forgery with adbe.pkcs7.sha1 SubFilter — LibreOfficeCWE-347 6.5 -2025-04-27
CVE-2021-25635 Content Manipulation with Certificate Validation Attack — LibreOfficeCWE-295 7.5 -2025-03-21
CVE-2025-1080 Macro URL arbitrary script execution — LibreOfficeCWE-20 8.8 -2025-03-04
CVE-2025-0514 Executable hyperlink Windows path targets executed unconditionally on activation — LibreOfficeCWE-20 6.5 -2025-02-25
CVE-2024-12426 URL fetching can be used to exfiltrate arbitrary INI file values and environment variables — LibreOfficeCWE-200 6.5 -2025-01-07
CVE-2024-12425 Path traversal leading to arbitrary .ttf file write — LibreOfficeCWE-22 6.2 -2025-01-07
CVE-2024-7788 Signatures in "repair mode" should not be trusted — LibreOfficeCWE-347 7.8 High2024-09-17
CVE-2024-6472 Ability to trust not validated macro signatures removed in high security mode — LibreOfficeCWE-295 7.8 High2024-08-05
CVE-2024-5261 TLS certificate are not properly verified when utilizing LibreOfficeKit — LibreOfficeCWE-295 9.1AICriticalAI2024-06-25
CVE-2024-3044 Graphic on-click binding allows unchecked script execution — LibreOfficeCWE-356 7.1 -2024-05-14
CVE-2023-6186 Link targets allow arbitrary script execution — LibreOffice 8.3 High2023-12-11
CVE-2023-6185 Improper input validation enabling arbitrary Gstreamer pipeline injection — LibreOffice 8.3 High2023-12-11
CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing — LibreOfficeCWE-129 8.8 -2023-05-25
CVE-2023-2255 Remote documents loaded without prompt via IFrame — LibreOfficeCWE-264 5.3 -2023-05-25
CVE-2022-3140 Macro URL arbitrary script execution — LibreOfficeCWE-20 7.6 -2022-10-11
CVE-2022-26307 Weak Master Keys — LibreOfficeCWE-326 8.8 -2022-07-25
CVE-2022-26305 Execution of Untrusted Macros Due to Improper Certificate Validation — LibreOfficeCWE-295 7.5 -2022-07-25
CVE-2022-26306 Execution of Untrusted Macros Due to Improper Certificate Validation — LibreOfficeCWE-326 9.1 -2022-07-25
CVE-2021-25636 Incorrect trust validation of signature with ambiguous KeyInfo children — LibreOfficeCWE-347 7.5 -2022-02-22
CVE-2021-25634 Timestamp Manipulation with Signature Wrapping — LibreOfficeCWE-295 7.5 -2021-10-12
CVE-2021-25633 Content Manipulation with Double Certificate Attack — LibreOfficeCWE-295 7.5 -2021-10-11

本页汇总了 The Document Foundation 厂商截至目前公开的全部 34 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。