Логотип exploitDog
bind:"GHSA-c683-7wh2-j8m4" OR bind:"CVE-2017-3157"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-c683-7wh2-j8m4" OR bind:"CVE-2017-3157"

Количество 8

Количество 8

github логотип

GHSA-c683-7wh2-j8m4

больше 3 лет назад

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send the document back to the attacker. The vulnerability is mitigated by the need for the attacker to know the precise file path in the target system, and the need to trick the user into saving the document and sending it back.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-3157

почти 8 лет назад

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send the document back to the attacker. The vulnerability is mitigated by the need for the attacker to know the precise file path in the target system, and the need to trick the user into saving the document and sending it back.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2017-3157

больше 8 лет назад

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send the document back to the attacker. The vulnerability is mitigated by the need for the attacker to know the precise file path in the target system, and the need to trick the user into saving the document and sending it back.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2017-3157

почти 8 лет назад

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send the document back to the attacker. The vulnerability is mitigated by the need for the attacker to know the precise file path in the target system, and the need to trick the user into saving the document and sending it back.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2017-3157

почти 8 лет назад

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded ...

CVSS3: 5.5
EPSS: Низкий
oracle-oval логотип

ELSA-2017-0979

больше 8 лет назад

ELSA-2017-0979: libreoffice security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2017-0914

больше 8 лет назад

ELSA-2017-0914: libreoffice security and bug fix update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2017-02018

больше 8 лет назад

Уязвимость компонентов Calc и Writer пакета офисных программ LibreOffice, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-c683-7wh2-j8m4

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send the document back to the attacker. The vulnerability is mitigated by the need for the attacker to know the precise file path in the target system, and the need to trick the user into saving the document and sending it back.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2017-3157

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send the document back to the attacker. The vulnerability is mitigated by the need for the attacker to know the precise file path in the target system, and the need to trick the user into saving the document and sending it back.

CVSS3: 5.5
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2017-3157

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send the document back to the attacker. The vulnerability is mitigated by the need for the attacker to know the precise file path in the target system, and the need to trick the user into saving the document and sending it back.

CVSS3: 4.7
1%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-3157

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send the document back to the attacker. The vulnerability is mitigated by the need for the attacker to know the precise file path in the target system, and the need to trick the user into saving the document and sending it back.

CVSS3: 5.5
1%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-3157

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded ...

CVSS3: 5.5
1%
Низкий
почти 8 лет назад
oracle-oval логотип
ELSA-2017-0979

ELSA-2017-0979: libreoffice security update (MODERATE)

больше 8 лет назад
oracle-oval логотип
ELSA-2017-0914

ELSA-2017-0914: libreoffice security and bug fix update (MODERATE)

больше 8 лет назад
fstec логотип
BDU:2017-02018

Уязвимость компонентов Calc и Writer пакета офисных программ LibreOffice, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.5
1%
Низкий
больше 8 лет назад

Уязвимостей на страницу