Логотип exploitDog
bind:"CVE-2020-12802" OR bind:"CVE-2020-12803"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2020-12802" OR bind:"CVE-2020-12803"

Количество 19

Количество 19

suse-cvrf логотип

openSUSE-SU-2020:1261-1

почти 5 лет назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1222-1

почти 5 лет назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2283-1

почти 5 лет назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2235-1

почти 5 лет назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2217-1

почти 5 лет назад

Security update for libreoffice

EPSS: Низкий
rocky логотип

RLSA-2020:4628

больше 4 лет назад

Low: libreoffice security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2020-4628

больше 4 лет назад

ELSA-2020-4628: libreoffice security, bug fix, and enhancement update (LOW)

EPSS: Низкий
ubuntu логотип

CVE-2020-12803

около 5 лет назад

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2020-12803

около 5 лет назад

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2020-12803

около 5 лет назад

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-12803

около 5 лет назад

ODF documents can contain forms to be filled out by the user. Similar ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2020-12802

около 5 лет назад

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents were omitted from this protection prior to version 6.4.4. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2020-12802

около 5 лет назад

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents were omitted from this protection prior to version 6.4.4. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-12802

около 5 лет назад

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents were omitted from this protection prior to version 6.4.4. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-12802

около 5 лет назад

LibreOffice has a 'stealth mode' in which only documents from location ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-r3c7-2c6p-8qmc

около 3 лет назад

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents were omitted from this protection prior to version 6.4.4. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-gxcj-pjgw-2hvw

около 3 лет назад

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2020-03673

около 5 лет назад

Уязвимость офисного пакета LibreOffice, связанная с некоректной проверкой вводимых данных, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2020-03672

около 5 лет назад

Уязвимость компонента «скрытый режим» офисного пакета LibreOffice, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
openSUSE-SU-2020:1261-1

Security update for libreoffice

почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1222-1

Security update for libreoffice

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2283-1

Security update for libreoffice

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2235-1

Security update for libreoffice

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2217-1

Security update for libreoffice

почти 5 лет назад
rocky логотип
RLSA-2020:4628

Low: libreoffice security, bug fix, and enhancement update

больше 4 лет назад
oracle-oval логотип
ELSA-2020-4628

ELSA-2020-4628: libreoffice security, bug fix, and enhancement update (LOW)

больше 4 лет назад
ubuntu логотип
CVE-2020-12803

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 6.5
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-12803

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 5.5
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-12803

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 6.5
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-12803

ODF documents can contain forms to be filled out by the user. Similar ...

CVSS3: 6.5
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-12802

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents were omitted from this protection prior to version 6.4.4. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 5.3
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-12802

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents were omitted from this protection prior to version 6.4.4. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 5.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-12802

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents were omitted from this protection prior to version 6.4.4. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 5.3
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-12802

LibreOffice has a 'stealth mode' in which only documents from location ...

CVSS3: 5.3
0%
Низкий
около 5 лет назад
github логотип
GHSA-r3c7-2c6p-8qmc

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents were omitted from this protection prior to version 6.4.4. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-gxcj-pjgw-2hvw

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2020-03673

Уязвимость офисного пакета LibreOffice, связанная с некоректной проверкой вводимых данных, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
0%
Низкий
около 5 лет назад
fstec логотип
BDU:2020-03672

Уязвимость компонента «скрытый режим» офисного пакета LibreOffice, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.3
0%
Низкий
около 5 лет назад

Уязвимостей на страницу