CVE-2026-63275Medium· 5.4▾ SunlitLibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the arra…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the array can hold wrote past its end. In fixed versions the hint count is checked against the capacity the array really has.
LibreOffice >= 26.2 < < 26.2.5Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63272Medium· 5.4Heap buffer overflow in WMF text record import
CVE-2026-63276Medium· 5.4Stack buffer overflow in CFF to Type 1 font conversion
CVE-2026-63273Medium· 5.4Heap buffer overflow in PDF import encryption handling
CVE-2026-63274Medium· 5.4Heap buffer overflow in PDF import stream handling
CVE-2026-63278Medium· 6.7Package URLs can be used to exfiltrate arbitrary INI file values and environment variables
CVE-2026-63279Medium· 5.4Out of bounds read in PICT image import