CVE-2024-3044

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/05/2024
Last modified:
10/12/2025

Description

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* 7.6.7.1 (excluding)
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* 24.2.0.0 (including) 24.2.3.1 (excluding)
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*