Known vulnerabilities in libreoffice (Debian package) 1:5.2.7-1+deb9u2~bpo8+1

Vendor: Debian
Version: 1:5.2.7-1+deb9u2~bpo8+1
Software CPE: cpe:2.3:o:debian:libreoffice_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 7
Public exploits: 2
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting libreoffice (Debian package) version 1:5.2.7-1+deb9u2~bpo8+1 libreoffice (Debian package) 1:5.2.7-1+deb9u2~bpo8+1 is affected by 7 vulnerabilities: 6 high, 1 low Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU20956 - Improper input validation
CVE-2019-9850
CWE-20 High
No
No
1:5.2.7-1+deb9u10, 1:6.1.5-3+deb10u3 10.09.2019 SB2019081530
SB2019090309
SB2019092505
and 5 more
#VU20955 - Improper Access Control
CVE-2019-9854
CWE-284 High
No
No
1:5.2.7-1+deb9u11, 1:6.1.5-3+deb10u4 10.09.2019 SB2019091014
SB2019092501
SB2019092505
and 5 more
#VU20861 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-9852
CWE-22 High
No
No
1:5.2.7-1+deb9u10, 1:6.1.5-3+deb10u3 04.09.2019 SB2019081530
SB2019090309
SB2019092505
and 5 more
#VU20860 - Improper input validation
CVE-2019-9851
CWE-20 High
Public exploit available
Exploited
1:5.2.7-1+deb9u10, 1:6.1.5-3+deb10u3 04.09.2019 SB2019081530
SB2019090309
SB2019092505
and 5 more
#VU19225 - Permissions, Privileges, and Access Controls
CVE-2019-9849
CWE-264 Low
No
No
1:5.2.7-1+deb9u9 17.07.2019 SB2019071703
SB2019071704
SB2019072301
and 10 more
#VU19223 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-9848
CWE-94 High
Public exploit available
Exploited
1:5.2.7-1+deb9u9 17.07.2019 SB2019071703
SB2019071704
SB2019072301
and 9 more
#VU17362 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-16858
CWE-22 High
Public exploit available
Exploited
1:5.2.7-1+deb9u5 04.02.2019 SB2019020401
SB2019020205
SB2019080611
and 2 more