Логотип exploitDog
bind:CVE-2020-12803
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-12803

Количество 13

Количество 13

ubuntu логотип

CVE-2020-12803

около 5 лет назад

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2020-12803

около 5 лет назад

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2020-12803

около 5 лет назад

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-12803

около 5 лет назад

ODF documents can contain forms to be filled out by the user. Similar ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gxcj-pjgw-2hvw

около 3 лет назад

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2020-03673

около 5 лет назад

Уязвимость офисного пакета LibreOffice, связанная с некоректной проверкой вводимых данных, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1261-1

почти 5 лет назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1222-1

почти 5 лет назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2283-1

почти 5 лет назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2235-1

почти 5 лет назад

Security update for libreoffice

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2217-1

почти 5 лет назад

Security update for libreoffice

EPSS: Низкий
rocky логотип

RLSA-2020:4628

больше 4 лет назад

Low: libreoffice security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2020-4628

больше 4 лет назад

ELSA-2020-4628: libreoffice security, bug fix, and enhancement update (LOW)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-12803

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 6.5
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-12803

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 5.5
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-12803

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 6.5
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-12803

ODF documents can contain forms to be filled out by the user. Similar ...

CVSS3: 6.5
0%
Низкий
около 5 лет назад
github логотип
GHSA-gxcj-pjgw-2hvw

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2020-03673

Уязвимость офисного пакета LibreOffice, связанная с некоректной проверкой вводимых данных, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
0%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1261-1

Security update for libreoffice

почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1222-1

Security update for libreoffice

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2283-1

Security update for libreoffice

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2235-1

Security update for libreoffice

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2217-1

Security update for libreoffice

почти 5 лет назад
rocky логотип
RLSA-2020:4628

Low: libreoffice security, bug fix, and enhancement update

больше 4 лет назад
oracle-oval логотип
ELSA-2020-4628

ELSA-2020-4628: libreoffice security, bug fix, and enhancement update (LOW)

больше 4 лет назад

Уязвимостей на страницу