Known vulnerabilities in libreoffice (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:libreoffice_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 29
Public exploits: 2
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting libreoffice (Debian package) libreoffice (Debian package) is affected by 29 known vulnerabilities: 19 high, 7 medium, 3 low Critical High Medium Low

Vulnerabilities (29)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU134747 - Heap-based Buffer Overflow
CVE-2026-6045
CWE-122 High
No
No
4:25.2.3-2+deb13u5 17.06.2026 SB2026061752
SB2026061753
SB2026071435
#VU134746 - Heap-based Buffer Overflow
CVE-2026-6039
CWE-122 High
No
No
4:25.2.3-2+deb13u5 17.06.2026 SB2026061752
SB2026061753
SB2026071435
#VU134745 - Use After Free
CVE-2026-6040
CWE-416 Low
No
No
4:25.2.3-2+deb13u5 17.06.2026 SB2026061752
SB2026061753
SB2026071435
#VU134744 - Heap-based Buffer Overflow
CVE-2026-8358
CWE-122 High
No
No
4:25.2.3-2+deb13u5 17.06.2026 SB2026061752
SB2026061753
SB2026071435
#VU134743 - Heap-based Buffer Overflow
CVE-2026-8357
CWE-122 High
No
No
4:25.2.3-2+deb13u5 17.06.2026 SB2026061752
SB2026061753
SB2026070839
and 5 more
#VU134742 - Stack-based buffer overflow
CVE-2026-8356
CWE-121 High
No
No
4:25.2.3-2+deb13u5 17.06.2026 SB2026061752
SB2026061753
SB2026071435
#VU133120 - Out-of-bounds write
CVE-2026-4430
CWE-787 High
No
No
4:7.4.7-1+deb12u11, 4:25.2.3-2+deb13u4 01.06.2026 SB2026060132
SB2026060136
SB2026060152
and 6 more
#VU107968 - Improper Verification of Cryptographic Signature
CVE-2025-2866
CWE-347 Medium
No
No
4:7.4.7-1+deb12u8 28.04.2025 SB2025042810
SB2025042901
SB2025050863
#VU105300 - Argument Injection or Modification
CVE-2025-1080
CWE-88 High
No
No
4:7.4.7-1+deb12u7 04.03.2025 SB2025030441
SB2025030506
SB2025031068
and 6 more
#VU102417 - Exposure of sensitive information to an unauthorized actor
CVE-2024-12426
CWE-200 Medium
No
No
4:7.4.7-1+deb12u6 07.01.2025 SB2025010746
SB2025012001
SB2025012779
and 1 more
#VU102416 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-12425
CWE-22 High
No
No
4:7.4.7-1+deb12u6 07.01.2025 SB2025010746
SB2025012001
SB2025012779
and 1 more
#VU97440 - Security Features
CVE-2024-7788
CWE-254 Medium
No
No
4:7.4.7-1+deb12u5 17.09.2024 SB2024091743
SB2024091901
SB2024091956
#VU95342 - Improper Certificate Validation
CVE-2024-6472
CWE-295 Medium
No
No
1:7.0.4-4+deb11u10, 4:7.4.7-1+deb12u4 05.08.2024 SB20240805107
SB2024080601
SB2024081578
and 3 more
#VU89492 - Security Features
CVE-2024-3044
CWE-254 High
No
No
1:7.0.4-4+deb11u9, 4:7.4.7-1+deb12u2 15.05.2024 SB2024051505
SB2024052133
SB2024052849
and 5 more
#VU84093 - Security Features
CVE-2023-6186
CWE-254 High
No
No
1:7.0.4-4+deb11u8, 4:7.4.7-1+deb12u1 12.12.2023 SB2023121213
SB2023121221
SB2023121223
and 16 more
#VU84092 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-6185
CWE-78 High
No
No
1:7.0.4-4+deb11u8, 4:7.4.7-1+deb12u1 12.12.2023 SB2023121210
SB2023121221
SB2023121223
and 18 more
#VU76613 - Insufficient UI Warning of Dangerous Operations
CVE-2023-2255
CWE-357 Medium
No
No
1:7.0.4-4+deb11u7 29.05.2023 SB2023052953
SB2023053001
SB2023060709
and 7 more
#VU76612 - Improper Validation of Array Index
CVE-2023-0950
CWE-129 High
No
No
1:7.0.4-4+deb11u7 29.05.2023 SB2023052952
SB2023053001
SB2023060709
and 7 more
#VU68115 - Command injection
CVE-2022-3140
CWE-77 High
No
No
1:7.0.4-4+deb11u4 11.10.2022 SB2022101127
SB2022101306
SB2022101830
and 7 more
#VU57213 - Improper Verification of Cryptographic Signature
CVE-2021-25634
CWE-347 Medium
No
No
1:7.0.4-4+deb11u1 11.10.2021 SB2021101113
SB2021101902
SB2022051139
and 2 more


Showing elements 1 - 20 out of 29