VulnSea

libreoffice vulnerabilities

CVEs whose affected-version data names the libreoffice package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

15 CVEsRSS

CVE-2026-63277High· 8.5
2d ago

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run…

▾ TwilightThe Document Foundation · LibreOfficevia NVD
CVE-2026-63270Medium· 6.7
2d ago

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-1242…

▾ SunlitThe Document Foundation · LibreOfficevia NVD
CVE-2026-63269Medium· 6.7
2d ago

LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer

LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist that made GStreamer read the local files and remote URLs it listed while the document …

▾ SunlitThe Document Foundation · LibreOfficevia NVD
CVE-2026-63268Medium· 6.7
2d ago

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder of local text files as a database, so opening a document could read a local text file in…

▾ SunlitThe Document Foundation · LibreOfficevia NVD
CVE-2026-63267Medium· 6.7
2d ago

LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document

LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a requ…

▾ SunlitThe Document Foundation · LibreOfficevia NVD
CVE-2026-63266Medium· 6.8
2d ago

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. …

▾ SunlitThe Document Foundation · LibreOfficevia NVD
CVE-2026-63275Medium· 5.4
2w ago

LibreOffice can read CFF fonts, which may be embedded in documents

LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the arra…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-63272Medium· 5.4
2w ago

LibreOffice can import WMF graphics, which may be embedded in documents

LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text we…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-63278Medium· 6.7
2w ago

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-1242…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.15%via NVD
CVE-2026-63276Medium· 5.4
2w ago

LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents

LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators we…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.19%via NVD
CVE-2026-63273Medium· 5.4
2w ago

LibreOffice Draw can import PDF documents

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size ke…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.11%via NVD
CVE-2026-63279Medium· 5.4
2w ago

LibreOffice can import PICT images, which may be embedded in documents

LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked against the…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-63274Medium· 5.4
2w ago

LibreOffice Draw can import PDF documents

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually presen…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-6045Medium· 5.4
3mo ago

Heap buffer overflow in EMF+ gradient brush import

LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to compute an allocation …

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via CVEORG
CVE-2025-14714Medium· 6.5
9mo ago

An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executi…

An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executi…

▾ Sunlitlibreoffice · libreofficeEPSS 0.14%via NVD
libreoffice vulnerabilities (CVEs) · VulnSea