Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-6186

Опубликовано: 11 дек. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.3

Описание

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

released

4:7.6.4-0ubuntu1
esm-infra/focal

not-affected

1:6.4.7-0ubuntu0.20.04.9
focal

released

1:6.4.7-0ubuntu0.20.04.9
jammy

released

1:7.3.7-0ubuntu0.22.04.4
lunar

released

4:7.5.9-0ubuntu0.23.04.1
mantic

released

4:7.6.4-0ubuntu0.23.10.1
trusty

ignored

end of standard support
upstream

released

7.5.9,7.6.4
xenial

ignored

end of standard support

Показывать по

EPSS

Процентиль: 78%
0.01179
Низкий

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
redhat
больше 1 года назад

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

CVSS3: 8.3
nvd
больше 1 года назад

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

CVSS3: 8.3
debian
больше 1 года назад

Insufficient macro permission validation of The Document Foundation Li ...

CVSS3: 8.3
github
больше 1 года назад

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

CVSS3: 8.3
fstec
больше 1 года назад

Уязвимость пакета офисных программ LibreOffice, связанная с возможностью внедрения кода или данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 78%
0.01179
Низкий

8.3 High

CVSS3