libreoffice libreoffice CVE-2018-14939 is a vulnerability in LibreOffice
Published on August 5, 2018

The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environments such as FreeBSD libc, which might allow attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact if LibreOffice is automatically launched during web browsing with pathnames controlled by a remote web site.

NVD


Products Associated with CVE-2018-14939

Want to know whenever a new CVE is published for LibreOffice? stack.watch will email you.

 

Exploit Probability

EPSS
2.22%
Percentile
81.87%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.