Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-3140
Description:LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.1; 7.3 versions prior to 7.3.6.
Test IDs: 1.3.6.1.4.1.25623.1.0.705252   1.3.6.1.4.1.25623.1.1.1.2.2023.3368   1.3.6.1.4.1.25623.1.0.822690   1.3.6.1.4.1.25623.1.1.10.2022.0400  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-3140
DSA-5252
https://www.debian.org/security/2022/dsa-5252
FEDORA-2022-775c747e4a
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TORANVTIWWBH3DNJR4UZATAG67KZOH32/
GLSA-202212-04
https://security.gentoo.org/glsa/202212-04
[debian-lts-announce] 20230326 [SECURITY] [DLA 3368-1] libreoffice security update
https://lists.debian.org/debian-lts-announce/2023/03/msg00022.html
https://www.libreoffice.org/about-us/security/advisories/CVE-2022-3140
https://www.libreoffice.org/about-us/security/advisories/CVE-2022-3140




© 1998-2025 E-Soft Inc. All rights reserved.