Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-3693

Опубликовано: 07 нояб. 2014
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.

Комментарий

CWE-416: Use After Free

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:a:libreoffice:libreoffice:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.0.3.3:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.0.4.2:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.3:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.4:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.5:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.6:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.3.0:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.3.1:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.3.2:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.05364
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
около 11 лет назад

Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.

redhat
около 11 лет назад

Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.

debian
около 11 лет назад

Use-after-free vulnerability in the socket manager of Impress Remote i ...

github
больше 3 лет назад

Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.

oracle-oval
больше 10 лет назад

ELSA-2015-0377: libreoffice security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 90%
0.05364
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other