Known vulnerabilities in libreoffice (Red Hat package)
Vendor:
Red Hat Inc.
Software:
libreoffice (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:libreoffice_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
27
Public exploits:
1
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
6.4.7.2-18.el8_6.2
7.1.8.1-15.el9_6.2
7.1.8.1-15.el9_4.2
6.4.7.2-18.el8_6.1
6.4.7.2-18.el8_8.1
6.4.7.2-18.el8_4.1
7.1.8.1-15.el9_8.2
6.4.7.2-20.el8_10
4.2.8.2-11.el6_7.1
5.0.6.2-5.el7_3.1
6.0.6.1-23.el8_2
6.4.7.2-18.el8_8
6.4.7.2-19.el8_10
6.0.6.1-22.el8_2
6.4.7.2-17.el8_4
7.1.8.1-12.el9_4
5.3.6.1-26.el7_9
6.4.7.2-16.el8_9
6.4.7.2-16.el8_8
6.0.6.1-21.el8_2
6.4.7.2-16.el8_4
6.4.7.2-16.el8_6
7.1.8.1-12.el9_3
7.1.8.1-12.el9_2
7.1.8.1-12.el9_0
6.4.7.2-15.el8
7.1.8.1-11.el9
7.1.8.1-8.el9_1
6.4.7.2-12.el8_7
6.4.7.2-11.el8
6.4.7.2-10.el8
6.3.6.2-3.el8
6.0.6.1-20.el8
5.3.6.1-24.el7
5.3.6.1-21.el7
5.3.6.1-19.el7
5.0.6.2-15.el7_4
5.0.6.2-14.el7
3.4.5.2-16.1.el6_3
4.2.6.3-5.el7
5.0.6.2-3.el7
4.3.7.2-2.el6_9
4.3.7.2-2.el6
4.2.8.2-11.el6_7
4.2.8.2-11.el6
4.0.4.2-14.el6
4.0.4.2-9.el6
3.4.5.2-16.el6
Vulnerabilities (27)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU134743 - Heap-based Buffer Overflow CVE-2026-8357 |
CWE-122 | High | 6.4.7.2-18.el8_6.2, 7.1.8.1-15.el9_4.2, 7.1.8.1-15.el9_6.2, 7.1.8.1-15.el9_8.2 | 17.06.2026 |
SB2026061752 SB2026061753 SB2026070839 and 5 more |
||
| #VU133120 - Out-of-bounds write CVE-2026-4430 |
CWE-787 | High | 6.4.7.2-18.el8_4.1, 6.4.7.2-18.el8_6.1, 6.4.7.2-18.el8_8.1, 6.4.7.2-20.el8_10 | 01.06.2026 |
SB2026060132 SB2026060136 SB2026060152 and 6 more |
||
| #VU105300 - Argument Injection or Modification CVE-2025-1080 |
CWE-88 | High | 6.0.6.1-23.el8_2, 6.4.7.2-18.el8_8, 6.4.7.2-19.el8_10 | 04.03.2025 |
SB2025030441 SB2025030506 SB2025031068 and 6 more |
||
| #VU95342 - Improper Certificate Validation CVE-2024-6472 |
CWE-295 | Medium | 6.0.6.1-22.el8_2, 6.4.7.2-17.el8_4 | 05.08.2024 |
SB20240805107 SB2024080601 SB2024081578 and 3 more |
||
| #VU84093 - Security Features CVE-2023-6186 |
CWE-254 | High | 6.0.6.1-21.el8_2, 6.4.7.2-16.el8_4, 6.4.7.2-16.el8_6, 6.4.7.2-16.el8_8, 6.4.7.2-16.el8_9, 7.1.8.1-12.el9_0, 7.1.8.1-12.el9_2, 7.1.8.1-12.el9_3, 7.1.8.1-12.el9_4 | 12.12.2023 |
SB2023121213 SB2023121221 SB2023121223 and 16 more |
||
| #VU84092 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2023-6185 |
CWE-78 | High | 5.3.6.1-26.el7_9, 6.0.6.1-21.el8_2, 6.4.7.2-16.el8_4, 6.4.7.2-16.el8_6, 6.4.7.2-16.el8_8, 6.4.7.2-16.el8_9, 7.1.8.1-12.el9_0, 7.1.8.1-12.el9_2, 7.1.8.1-12.el9_3, 7.1.8.1-12.el9_4 | 12.12.2023 |
SB2023121210 SB2023121221 SB2023121223 and 18 more |
||
| #VU77534 - External Control of File Name or Path CVE-2023-1183 |
CWE-73 | High | 6.4.7.2-15.el8, 7.1.8.1-11.el9 | 20.06.2023 |
SB2023062004 SB2023062203 SB2023062204 and 14 more |
||
| #VU76613 - Insufficient UI Warning of Dangerous Operations CVE-2023-2255 |
CWE-357 | Medium | 6.4.7.2-15.el8, 7.1.8.1-11.el9 | 29.05.2023 |
SB2023052953 SB2023053001 SB2023060709 and 7 more |
||
| #VU76612 - Improper Validation of Array Index CVE-2023-0950 |
CWE-129 | High | 6.4.7.2-15.el8, 7.1.8.1-11.el9 | 29.05.2023 |
SB2023052952 SB2023053001 SB2023060709 and 7 more |
||
| #VU74031 - Improper Control of Generation of Code ('Code Injection') CVE-2022-38745 |
CWE-94 | High | 6.4.7.2-15.el8, 7.1.8.1-11.el9 | 25.03.2023 |
SB2023032503 SB2023032504 SB2023041723 and 4 more |
||
| #VU68115 - Command injection CVE-2022-3140 |
CWE-77 | High | 6.4.7.2-12.el8_7, 7.1.8.1-8.el9_1 | 11.10.2022 |
SB2022101127 SB2022101306 SB2022101830 and 7 more |
||
| #VU65768 - Inadequate Encryption Strength CVE-2022-26307 |
CWE-326 | Low | 6.4.7.2-12.el8_7, 7.1.8.1-8.el9_1 | 25.07.2022 |
SB2022072548 SB2022100634 SB2022101830 and 5 more |
||
| #VU65767 - Inadequate Encryption Strength CVE-2022-26306 |
CWE-326 | Low | 6.4.7.2-12.el8_7, 7.1.8.1-8.el9_1 | 25.07.2022 |
SB2022072548 SB2022100634 SB2022102080 and 3 more |
||
| #VU65760 - Improper Certificate Validation CVE-2022-26305 |
CWE-295 | Medium | 6.4.7.2-12.el8_7, 7.1.8.1-8.el9_1 | 25.07.2022 |
SB2022072520 SB2022100634 SB2022101830 and 5 more |
||
| #VU60762 - Improper Certificate Validation CVE-2021-25636 |
CWE-295 | Low | 6.4.7.2-11.el8 | 22.02.2022 |
SB2022022217 SB2022031624 SB2022110838 and 4 more |
||
| #VU57214 - Improper Certificate Validation CVE-2021-25633 |
CWE-295 | Medium | 6.4.7.2-10.el8 | 11.10.2021 |
SB2021101113 SB2021101902 SB2022051139 and 2 more |
||
| #VU57213 - Improper Verification of Cryptographic Signature CVE-2021-25634 |
CWE-347 | Medium | 6.4.7.2-10.el8 | 11.10.2021 |
SB2021101113 SB2021101902 SB2022051139 and 2 more |
||
| #VU57212 - Improper Verification of Cryptographic Signature CVE-2021-25635 |
CWE-347 | Medium | 6.4.7.2-10.el8 | 11.10.2021 |
SB2021101112 SB2022051139 SB20220615127 |
||
| #VU28800 - Improper input validation CVE-2020-12803 |
CWE-20 | Medium | 6.3.6.2-3.el8 | 09.06.2020 |
SB2020060912 SB2020081601 SB2020082707 and 3 more |
||
| #VU28799 - Permissions, Privileges, and Access Controls CVE-2020-12802 |
CWE-264 | Medium | 6.3.6.2-3.el8 | 09.06.2020 |
SB2020060912 SB2020081601 SB2020082707 and 2 more |
Showing elements 1 - 20 out of 27