Search CVE reports


Toggle filters

11 – 20 of 116 results


CVE-2026-63274

Medium priority

Some fixes available 3 of 4

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation —
Show less packages

CVE-2026-63273

Medium priority

Some fixes available 3 of 4

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation —
Show less packages

CVE-2026-63272

Medium priority

Some fixes available 3 of 4

LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation —
Show less packages

CVE-2026-8358

Medium priority

Some fixes available 3 of 5

LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identifier for two different kinds of change. The importer then treated one change...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation —
Show less packages

CVE-2026-8357

Medium priority

Some fixes available 3 of 5

LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation —
Show less packages

CVE-2026-8356

Medium priority

Some fixes available 3 of 5

LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a colour-replacement record. Two fixed-size colour tables were filled from the file, but the write position was...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation —
Show less packages

CVE-2026-6047

Medium priority
Fixed

LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Not affected Not affected Not affected —
Show less packages

CVE-2026-6045

Medium priority

Some fixes available 3 of 5

LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to compute an...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation —
Show less packages

CVE-2026-6040

Medium priority

Some fixes available 2 of 3

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Not affected Not affected —
Show less packages

CVE-2026-6039

Medium priority

Some fixes available 3 of 5

LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point count taken from the file was truncated to a 16-bit value when the point buffer was...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation —
Show less packages