CVE-2024-3044
—CVSS 3.1
6.5 medium
EPSS
1%p61
Published
()
Modified
Description
Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.
- Vendors
- libreofficefedoraprojectdebian
- Products
- libreoffice, fedora, debian linux
- Weakness
- CWE-356, CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.