Known vulnerabilities in libreoffice (Ubuntu package)

Software CPE: cpe:2.3:o:canonical:libreoffice_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Total vulnerabilities: 27
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting libreoffice (Ubuntu package) libreoffice (Ubuntu package) is affected by 27 known vulnerabilities: 15 high, 8 medium, 4 low Critical High Medium Low

Vulnerabilities (27)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU134747 - Heap-based Buffer Overflow
CVE-2026-6045
CWE-122 High
No
No
1:7.3.7-0ubuntu0.22.04.12, 4:24.2.7-0ubuntu0.24.04.6, 4:26.2.4.2-0ubuntu0.26.04.2 17.06.2026 SB2026061752
SB2026061753
SB2026071435
#VU134746 - Heap-based Buffer Overflow
CVE-2026-6039
CWE-122 High
No
No
1:7.3.7-0ubuntu0.22.04.12, 4:24.2.7-0ubuntu0.24.04.6, 4:26.2.4.2-0ubuntu0.26.04.2 17.06.2026 SB2026061752
SB2026061753
SB2026071435
#VU134745 - Use After Free
CVE-2026-6040
CWE-416 Low
No
No
1:7.3.7-0ubuntu0.22.04.12, 4:24.2.7-0ubuntu0.24.04.6, 4:26.2.4.2-0ubuntu0.26.04.2 17.06.2026 SB2026061752
SB2026061753
SB2026071435
#VU134744 - Heap-based Buffer Overflow
CVE-2026-8358
CWE-122 High
No
No
1:7.3.7-0ubuntu0.22.04.12, 4:24.2.7-0ubuntu0.24.04.6, 4:26.2.4.2-0ubuntu0.26.04.2 17.06.2026 SB2026061752
SB2026061753
SB2026071435
#VU134743 - Heap-based Buffer Overflow
CVE-2026-8357
CWE-122 High
No
No
1:7.3.7-0ubuntu0.22.04.12, 4:24.2.7-0ubuntu0.24.04.6, 4:26.2.4.2-0ubuntu0.26.04.2 17.06.2026 SB2026061752
SB2026061753
SB2026070839
and 5 more
#VU134742 - Stack-based buffer overflow
CVE-2026-8356
CWE-121 High
No
No
1:7.3.7-0ubuntu0.22.04.12, 4:24.2.7-0ubuntu0.24.04.6, 4:26.2.4.2-0ubuntu0.26.04.2 17.06.2026 SB2026061752
SB2026061753
SB2026071435
#VU133120 - Out-of-bounds write
CVE-2026-4430
CWE-787 High
No
No
1:7.3.7-0ubuntu0.22.04.11, 4:24.2.7-0ubuntu0.24.04.5, 4:25.8.7-0ubuntu0.25.10.1, 4:26.2.3.2-0ubuntu0.26.04.1 01.06.2026 SB2026060132
SB2026060136
SB2026060152
and 6 more
#VU107968 - Improper Verification of Cryptographic Signature
CVE-2025-2866
CWE-347 Medium
No
No
1:6.4.7-0ubuntu0.20.04.15, 1:7.3.7-0ubuntu0.22.04.10, 4:24.2.7-0ubuntu0.24.04.4, 4:24.8.6-0ubuntu0.24.10.2 28.04.2025 SB2025042810
SB2025042901
SB2025050863
#VU105300 - Argument Injection or Modification
CVE-2025-1080
CWE-88 High
No
No
1:6.4.7-0ubuntu0.20.04.14, 1:7.3.7-0ubuntu0.22.04.9, 4:24.2.7-0ubuntu0.24.04.3, 4:24.8.5-0ubuntu0.24.10.2 04.03.2025 SB2025030441
SB2025030506
SB2025031068
and 6 more
#VU102417 - Exposure of sensitive information to an unauthorized actor
CVE-2024-12426
CWE-200 Medium
No
No
1:6.4.7-0ubuntu0.20.04.13, 1:7.3.7-0ubuntu0.22.04.8, 4:24.2.7-0ubuntu0.24.04.2, 4:24.8.4-0ubuntu0.24.10.2 07.01.2025 SB2025010746
SB2025012001
SB2025012779
and 1 more
#VU102416 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-12425
CWE-22 High
No
No
1:6.4.7-0ubuntu0.20.04.13, 1:7.3.7-0ubuntu0.22.04.8, 4:24.2.7-0ubuntu0.24.04.2, 4:24.8.4-0ubuntu0.24.10.2 07.01.2025 SB2025010746
SB2025012001
SB2025012779
and 1 more
#VU97440 - Security Features
CVE-2024-7788
CWE-254 Medium
No
No
1:6.4.7-0ubuntu0.20.04.12, 1:7.3.7-0ubuntu0.22.04.7 17.09.2024 SB2024091743
SB2024091901
SB2024091956
#VU95342 - Improper Certificate Validation
CVE-2024-6472
CWE-295 Medium
No
No
1:6.4.7-0ubuntu0.20.04.11, 1:7.3.7-0ubuntu0.22.04.6, 4:24.2.5-0ubuntu0.24.04.2 05.08.2024 SB20240805107
SB2024080601
SB2024081578
and 3 more
#VU93313 - Improper Certificate Validation
CVE-2024-5261
CWE-295 Medium
No
No
4:7.6.7-0ubuntu0.23.10.3, 4:24.2.4-0ubuntu0.24.04.2 25.06.2024 SB20240625112
SB2024070492
SB2024101036
and 1 more
#VU89492 - Security Features
CVE-2024-3044
CWE-254 High
No
No
1:6.4.7-0ubuntu0.20.04.10, 1:7.3.7-0ubuntu0.22.04.5, 4:7.6.7-0ubuntu0.23.10.2, 4:24.2.3-0ubuntu0.24.04.2 15.05.2024 SB2024051505
SB2024052133
SB2024052849
and 5 more
#VU84093 - Security Features
CVE-2023-6186
CWE-254 High
No
No
1:6.4.7-0ubuntu0.20.04.9, 1:7.3.7-0ubuntu0.22.04.4, 4:7.5.9-0ubuntu0.23.04.1, 4:7.6.4-0ubuntu0.23.10.1 12.12.2023 SB2023121213
SB2023121221
SB2023121223
and 16 more
#VU84092 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-6185
CWE-78 High
No
No
1:6.4.7-0ubuntu0.20.04.9, 1:7.3.7-0ubuntu0.22.04.4, 4:7.5.9-0ubuntu0.23.04.1, 4:7.6.4-0ubuntu0.23.10.1 12.12.2023 SB2023121210
SB2023121221
SB2023121223
and 18 more
#VU76613 - Insufficient UI Warning of Dangerous Operations
CVE-2023-2255
CWE-357 Medium
No
No
1:6.4.7-0ubuntu0.20.04.8, 1:7.3.7-0ubuntu0.22.04.3 29.05.2023 SB2023052953
SB2023053001
SB2023060709
and 7 more
#VU76612 - Improper Validation of Array Index
CVE-2023-0950
CWE-129 High
No
No
1:6.4.7-0ubuntu0.20.04.8, 1:7.3.7-0ubuntu0.22.04.3 29.05.2023 SB2023052952
SB2023053001
SB2023060709
and 7 more
#VU74031 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-38745
CWE-94 High
No
No
1:6.0.7-0ubuntu0.18.04.13, 1:6.4.7-0ubuntu0.20.04.7 25.03.2023 SB2023032503
SB2023032504
SB2023041723
and 4 more


Showing elements 1 - 20 out of 27