Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-3044


Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.


Published

2024-05-14T21:15:12.627

Last Modified

2025-12-10T19:10:17.363

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-356
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application libreoffice libreoffice < 7.6.7.1 Yes
Application libreoffice libreoffice < 24.2.3.1 Yes
Operating System fedoraproject fedora 39 Yes
Operating System debian debian_linux 10.0 Yes

References