libreoffice vulnerabilities
CVEs whose affected-version data names the libreoffice package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
15 CVEsRSS
CVE-2026-63277High· 8.5LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run…
CVE-2026-63270Medium· 6.7URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links
URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-1242…
CVE-2026-63269Medium· 6.7LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer
LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist that made GStreamer read the local files and remote URLs it listed while the document …
CVE-2026-63268Medium· 6.7LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder of local text files as a database, so opening a document could read a local text file in…
CVE-2026-63267Medium· 6.7LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document
LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a requ…
CVE-2026-63266Medium· 6.8LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. …
CVE-2026-63275Medium· 5.4LibreOffice can read CFF fonts, which may be embedded in documents
LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the arra…
CVE-2026-63272Medium· 5.4LibreOffice can import WMF graphics, which may be embedded in documents
LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text we…
CVE-2026-63278Medium· 6.7URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links
URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-1242…
CVE-2026-63276Medium· 5.4LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents
LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators we…
CVE-2026-63273Medium· 5.4LibreOffice Draw can import PDF documents
LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size ke…
CVE-2026-63279Medium· 5.4LibreOffice can import PICT images, which may be embedded in documents
LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked against the…
CVE-2026-63274Medium· 5.4LibreOffice Draw can import PDF documents
LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually presen…
CVE-2026-6045Medium· 5.4Heap buffer overflow in EMF+ gradient brush import
LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to compute an allocation …
CVE-2025-14714Medium· 6.5An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executi…
An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executi…