<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:55:57.623118+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2020:4628</id>
    <title>ALSA-2020:4628 — Low: libreoffice security, bug fix, and enhancement update</title>
    <updated>2026-10-04T09:55:57.668485+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: libcmis, AlmaLinux:8: libreoffice-sdk, AlmaLinux:8: libreoffice-sdk-doc</p>
<p>LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.</p>
<p>The following packages have been upgraded to a later upstream version: libreoffice (6.3.6.2), libcmis (0.5.2), liborcus (0.14.1). (BZ#1796893)</p>
<p>Security Fix(es):</p>
<p>* libreoffice: 'stealth mode' remote resource restrictions bypass (CVE-2020-12802)</p>
<p>* libreoffice: forms allowed to be submitted to any URI could result in local file overwrite (CVE-2020-12803)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2020:4628"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-03673</id>
    <title>bdu:2020-03673</title>
    <updated>2026-10-04T09:55:57.668564+00:00</updated>
    <content>bdu:2020-03673</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-03673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-35943</id>
    <title>cnvd-2020-35943</title>
    <updated>2026-10-04T09:55:57.668582+00:00</updated>
    <content>cnvd-2020-35943</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-35943"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-174130</id>
    <title>EUVD-2026-174130</title>
    <updated>2026-10-04T09:55:57.668595+00:00</updated>
    <content>EUVD-2026-174130</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-174130"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-12803</id>
    <title>fkie_cve-2020-12803</title>
    <updated>2026-10-04T09:55:57.668606+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-12803"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gxcj-pjgw-2hvw</id>
    <title>GHSA-gxcj-pjgw-2hvw</title>
    <updated>2026-10-04T09:55:57.668631+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gxcj-pjgw-2hvw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-12803</id>
    <title>gsd-2020-12803</title>
    <updated>2026-10-04T09:55:57.668649+00:00</updated>
    <content>gsd-2020-12803</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-12803"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1222-1</id>
    <title>openSUSE-SU-2020:1222-1 — Security update for libreoffice</title>
    <updated>2026-10-04T09:55:57.668659+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libreoffice</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:1222-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:4628</id>
    <title>RHSA-2020:4628 — Red Hat Security Advisory: libreoffice security, bug fix, and enhancement update</title>
    <updated>2026-10-04T09:55:57.668678+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libreoffice: 'stealth mode' remote resource restrictions bypass libreoffice: forms allowed to be submitted to any URI could result in local file overwrite</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:4628"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:2217-1</id>
    <title>SUSE-SU-2020:2217-1 — Security update for libreoffice</title>
    <updated>2026-10-04T09:55:57.668695+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libreoffice</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:2217-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-12803</id>
    <title>UBUNTU-CVE-2020-12803</title>
    <updated>2026-10-04T09:55:57.668710+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: libreoffice, Ubuntu:20.04:LTS: libreoffice</p>
<p>ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-12803"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1808</id>
    <title>WID-SEC-W-2022-1808 — LibreOffice: Mehrere Schwachstellen</title>
    <updated>2026-10-04T09:55:57.668734+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in LibreOffice ausnutzen, um Sicherheitsvorkehrungen zu umgehen und um Dateien zu überschreiben.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1808"/>
  </entry>
</feed>
