<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 09:00:54 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:4628 — Low: libreoffice security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:4628</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libcmis, AlmaLinux:8: libreoffice-sdk, AlmaLinux:8: libreoffice-sdk-doc&lt;/p&gt;
&lt;p&gt;LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: libreoffice (6.3.6.2), libcmis (0.5.2), liborcus (0.14.1). (BZ#1796893)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libreoffice: &amp;#39;stealth mode&amp;#39; remote resource restrictions bypass (CVE-2020-12802)&lt;/p&gt;
&lt;p&gt;* libreoffice: forms allowed to be submitted to any URI could result in local file overwrite (CVE-2020-12803)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libcmis, AlmaLinux:8: libreoffice-sdk, AlmaLinux:8: libreoffice-sdk-doc&lt;/p&gt;
&lt;p&gt;LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: libreoffice (6.3.6.2), libcmis (0.5.2), liborcus (0.14.1). (BZ#1796893)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libreoffice: &amp;#39;stealth mode&amp;#39; remote resource restrictions bypass (CVE-2020-12802)&lt;/p&gt;
&lt;p&gt;* libreoffice: forms allowed to be submitted to any URI could result in local file overwrite (CVE-2020-12803)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:4628</guid>
    </item>
    <item>
      <title>bdu:2020-03673</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-03673</link>
      <description>bdu:2020-03673</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-03673</guid>
    </item>
    <item>
      <title>cnvd-2020-35943</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-35943</link>
      <description>cnvd-2020-35943</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-35943</guid>
    </item>
    <item>
      <title>EUVD-2026-174130</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-174130</link>
      <description>EUVD-2026-174130</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-174130</guid>
    </item>
    <item>
      <title>fkie_cve-2020-12803</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-12803</link>
      <description>&lt;p&gt;ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-12803</guid>
    </item>
    <item>
      <title>GHSA-gxcj-pjgw-2hvw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gxcj-pjgw-2hvw</link>
      <description>&lt;p&gt;ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gxcj-pjgw-2hvw</guid>
    </item>
    <item>
      <title>gsd-2020-12803</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-12803</link>
      <description>gsd-2020-12803</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-12803</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:1222-1 — Security update for libreoffice</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1222-1</link>
      <description>&lt;p&gt;Security update for libreoffice&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libreoffice&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:1222-1</guid>
    </item>
    <item>
      <title>RHSA-2020:4628 — Red Hat Security Advisory: libreoffice security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:4628</link>
      <description>&lt;p&gt;libreoffice: &amp;#39;stealth mode&amp;#39; remote resource restrictions bypass libreoffice: forms allowed to be submitted to any URI could result in local file overwrite&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libreoffice: &amp;#39;stealth mode&amp;#39; remote resource restrictions bypass libreoffice: forms allowed to be submitted to any URI could result in local file overwrite&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:4628</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:2217-1 — Security update for libreoffice</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:2217-1</link>
      <description>&lt;p&gt;Security update for libreoffice&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libreoffice&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:2217-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-12803</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-12803</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: libreoffice, Ubuntu:20.04:LTS: libreoffice&lt;/p&gt;
&lt;p&gt;ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: libreoffice, Ubuntu:20.04:LTS: libreoffice&lt;/p&gt;
&lt;p&gt;ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-12803</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1808 — LibreOffice: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1808</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in LibreOffice ausnutzen, um Sicherheitsvorkehrungen zu umgehen und um Dateien zu überschreiben.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in LibreOffice ausnutzen, um Sicherheitsvorkehrungen zu umgehen und um Dateien zu überschreiben.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1808</guid>
    </item>
  </channel>
</rss>
