← Back

CVE-2024-3044

nvd nist
Published: May 14, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.

Affected (4)

1 product
Libreoffice
1 product
Fedora
1 product
Debian Linux
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Libreoffice
Before 7.6.7.1
From 24.2.0.0 to 24.2.3.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 39
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0

References (6)

Source: security@documentfoundation.org
Mailing ListThird Party Advisory
Source: security@documentfoundation.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.