CVE-2026-63272Medium· 5.4▾ SunlitLibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text we…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were read separately from the file and were not required to agree, so drawing the text walked the advance array by character position and ran past its end when the array was the shorter of the two. In fixed versions an advance array shorter than its text is ignored.
LibreOffice >= 26.2 < < 26.2.5Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63274Medium· 5.4Heap buffer overflow in PDF import stream handling
CVE-2026-63275Medium· 5.4Stack buffer overflow in CFF font hint handling
CVE-2026-63276Medium· 5.4Stack buffer overflow in CFF to Type 1 font conversion
CVE-2026-63273Medium· 5.4Heap buffer overflow in PDF import encryption handling
CVE-2026-63279Medium· 5.4Out of bounds read in PICT image import
CVE-2026-63278Medium· 6.7Package URLs can be used to exfiltrate arbitrary INI file values and environment variables