CVE-2015-5214 is a denial-of-service and arbitrary code execution vulnerability affecting LibreOffice before 4.4.6 and 5.x before 5.0.1, and Apache OpenOffice before 4.1.2. The vulnerability, rated with a CVSS score of 6.8, allows remote attackers to trigger memory corruption and application crashes or execute arbitrary code by exploiting a non-existent bookmark index in a DOC file. While the EPSS score is relatively high, indicating potential exploitability, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
15.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
libreoffice: Bookmarks in DOC documents are insufficiently checked causing memory corruption
Nov 4, 2015DOC Bookmark Status Memory Corruption
DOC Bookmark Status Memory Corruption
.DOC Bookmarks Vulnerability
.DOC Bookmarks Vulnerability
.DOC Bookmarks Vulnerability
.DOC Bookmarks Vulnerability