<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:56:34 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:6508 — Moderate: libreoffice security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:6508</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: autocorr-af, AlmaLinux:9: autocorr-bg, AlmaLinux:9: autocorr-ca, AlmaLinux:9: autocorr-cs, AlmaLinux:9: autocorr-da, AlmaLinux:9: autocorr-de, AlmaLinux:9: autocorr-dsb, AlmaLinux:9: autocorr-el, AlmaLinux:9: autocorr-en, AlmaLinux:9: autocorr-es and 169 more&lt;/p&gt;
&lt;p&gt;LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libreoffice: Empty entry in Java class path (CVE-2022-38745)
* libreoffice: Array index underflow in Calc formula parsing (CVE-2023-0950)
* libreoffice: Arbitrary file write (CVE-2023-1183)
* libreoffice: Remote documents loaded without prompt via IFrame (CVE-2023-2255)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: autocorr-af, AlmaLinux:9: autocorr-bg, AlmaLinux:9: autocorr-ca, AlmaLinux:9: autocorr-cs, AlmaLinux:9: autocorr-da, AlmaLinux:9: autocorr-de, AlmaLinux:9: autocorr-dsb, AlmaLinux:9: autocorr-el, AlmaLinux:9: autocorr-en, AlmaLinux:9: autocorr-es and 169 more&lt;/p&gt;
&lt;p&gt;LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libreoffice: Empty entry in Java class path (CVE-2022-38745)
* libreoffice: Array index underflow in Calc formula parsing (CVE-2023-0950)
* libreoffice: Arbitrary file write (CVE-2023-1183)
* libreoffice: Remote documents loaded without prompt via IFrame (CVE-2023-2255)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:6508</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0477 — Une vulnérabilité a été découverte dans&lt;span class="textit"&gt;
LibreOffice&lt;/span&gt;. Elle permet à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0477</link>
      <description>certfr-2023-avi-0477</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0477</guid>
    </item>
    <item>
      <title>EUVD-2026-216146</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-216146</link>
      <description>EUVD-2026-216146</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-216146</guid>
    </item>
    <item>
      <title>fkie_cve-2023-1183</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-1183</link>
      <description>&lt;p&gt;A flaw was found in the Libreoffice package. An attacker can craft an odb containing a &amp;#34;database/script&amp;#34; file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Libreoffice package. An attacker can craft an odb containing a &amp;#34;database/script&amp;#34; file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-1183</guid>
    </item>
    <item>
      <title>GHSA-5f9q-hg2v-3887</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5f9q-hg2v-3887</link>
      <description>&lt;p&gt;A flaw was found in the Libreoffice package. An attacker can craft an odb containing a &amp;#34;database/script&amp;#34; file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Libreoffice package. An attacker can craft an odb containing a &amp;#34;database/script&amp;#34; file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5f9q-hg2v-3887</guid>
    </item>
    <item>
      <title>gsd-2023-1183</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-1183</link>
      <description>gsd-2023-1183</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-1183</guid>
    </item>
    <item>
      <title>OESA-2026-1430 — hsqldb security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1430</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: hsqldb&lt;/p&gt;
&lt;p&gt;HSQLdb is a relational database engine written in JavaTM , with a JDBC driver, supporting a subset of ANSI-92 SQL. It offers a small (about 100k), fast database engine which offers both in memory and disk based tables. Embedded and server modes are available. Additionally, it includes tools such as a minimal web server, in-memory query and management tools (can be run as applets or servlets, too) and a number of demonstration examples. Downloaded code should be regarded as being of production quality. The product is currently being used as a database and persistence engine in many Open Source Software projects and even in commercial projects and products! In it&amp;amp;amp;apos;s current version it is extremely stable and reliable. It is best known for its small size, ability to execute completely in memory and its speed. Yet it is a completely functional relational database management system that is completely free under the Modified BSD License. Yes, that&amp;amp;amp;apos;s right, completely free of cost or restrictions!&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in the Libreoffice package. An attacker can craft an odb containing a &amp;amp;quot;database/script&amp;amp;quot; file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.(CVE-2023-1183)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: hsqldb&lt;/p&gt;
&lt;p&gt;HSQLdb is a relational database engine written in JavaTM , with a JDBC driver, supporting a subset of ANSI-92 SQL. It offers a small (about 100k), fast database engine which offers both in memory and disk based tables. Embedded and server modes are available. Additionally, it includes tools such as a minimal web server, in-memory query and management tools (can be run as applets or servlets, too) and a number of demonstration examples. Downloaded code should be regarded as being of production quality. The product is currently being used as a database and persistence engine in many Open Source Software projects and even in commercial projects and products! In it&amp;amp;amp;apos;s current version it is extremely stable and reliable. It is best known for its small size, ability to execute completely in memory and its speed. Yet it is a completely functional relational database management system that is completely free under the Modified BSD License. Yes, that&amp;amp;amp;apos;s right, completely free of cost or restrictions!&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in the Libreoffice package. An attacker can craft an odb containing a &amp;amp;quot;database/script&amp;amp;quot; file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.(CVE-2023-1183)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1430</guid>
    </item>
    <item>
      <title>RHSA-2023:6508 — Red Hat Security Advisory: libreoffice security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:6508</link>
      <description>&lt;p&gt;libreoffice: Empty entry in Java class path libreoffice: Array index underflow in Calc formula parsing libreoffice: Arbitrary file write libreoffice: Remote documents loaded without prompt via IFrame&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libreoffice: Empty entry in Java class path libreoffice: Array index underflow in Calc formula parsing libreoffice: Arbitrary file write libreoffice: Remote documents loaded without prompt via IFrame&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:6508</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:4648-1 — Security update for libreoffice</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:4648-1</link>
      <description>&lt;p&gt;Security update for libreoffice&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libreoffice&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:4648-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-1183</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-1183</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: hsqldb1.8.0, Ubuntu:Pro:18.04:LTS: hsqldb1.8.0, Ubuntu:Pro:20.04:LTS: hsqldb1.8.0, Ubuntu:22.04:LTS: hsqldb1.8.0&lt;/p&gt;
&lt;p&gt;A flaw was found in the Libreoffice package. An attacker can craft an odb containing a &amp;#34;database/script&amp;#34; file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: hsqldb1.8.0, Ubuntu:Pro:18.04:LTS: hsqldb1.8.0, Ubuntu:Pro:20.04:LTS: hsqldb1.8.0, Ubuntu:22.04:LTS: hsqldb1.8.0&lt;/p&gt;
&lt;p&gt;A flaw was found in the Libreoffice package. An attacker can craft an odb containing a &amp;#34;database/script&amp;#34; file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-1183</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1496 — LibreOffice: Schwachstelle ermöglicht Erzeugung von Dateien</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1496</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in LibreOffice ausnutzen, um Dateien zu erzeugen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in LibreOffice ausnutzen, um Dateien zu erzeugen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1496</guid>
    </item>
  </channel>
</rss>
