AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-9850

CRITICAL · CVSS 9.8 EPSS 3.37%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-08-15 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Office.

CVE
CVE-2019-9850
Severity
CRITICAL
CVSS
9.8
EPSS
3.37%
Office

Original NVD Description

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script events such as mouse-over, etc. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from script event handers. However an insufficient url validation vulnerability in LibreOffice allowed malicious to bypass that protection and again trigger calling LibreLogo from script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.

Related CVEs

Other vulnerabilities affecting the same vendor(s)