LibreOffice
The Document Foundation · 56 CVEs
RCE via calcext:data-mappings, sql provider and jdbc connector
Oct 5, 2026
Environment/ini-file leaks
Oct 5, 2026
LFI and GET SSRF via GStreamer and HLS playlists
Oct 5, 2026
LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href
Oct 5, 2026
LFI and GET SSRF via calcext:data-mappings and csv provider
Oct 5, 2026
Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality
Oct 5, 2026
Out of bounds read in PICT image import
Sep 22, 2026
Package URLs can be used to exfiltrate arbitrary INI file values and environment variables
Sep 22, 2026
Stack buffer overflow in CFF to Type 1 font conversion
Sep 22, 2026
Stack buffer overflow in CFF font hint handling
Sep 22, 2026
Heap buffer overflow in PDF import stream handling
Sep 22, 2026
Heap buffer overflow in PDF import encryption handling
Sep 22, 2026
Heap buffer overflow in WMF text record import
Sep 22, 2026
Heap buffer overflow in spreadsheet tracked-changes import
Jun 15, 2026
Heap buffer overflow in Calc formula compilation
Jun 15, 2026
Stack buffer overflow in PPT presentation import
Jun 15, 2026
Heap buffer overflow in OOXML text box element import
Jun 15, 2026
Heap buffer overflow in EMF+ gradient brush import
Jun 15, 2026
Heap use-after-free in ODF number-format blank-width parsing
Jun 15, 2026
Heap buffer overflow in DXF polyline import
Jun 15, 2026
Heap Buffer Overflow in AgileEngine
May 7, 2026
TCC Bypass via Inherited Permissions in Bundled Interpreter
Dec 15, 2025
PDF signature forgery with adbe.pkcs7.sha1 SubFilter
Apr 27, 2025
Content Manipulation with Certificate Validation Attack
Mar 21, 2025
Macro URL arbitrary script execution
Mar 4, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-63277 | RCE via calcext:data-mappings, sql provider and jdbc connector | HIGH | 0.14% | Oct 5, 2026 |
| CVE-2026-63270 | Environment/ini-file leaks | MEDIUM | 0.12% | Oct 5, 2026 |
| CVE-2026-63269 | LFI and GET SSRF via GStreamer and HLS playlists | MEDIUM | 0.11% | Oct 5, 2026 |
| CVE-2026-63268 | LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href | MEDIUM | 0.12% | Oct 5, 2026 |
| CVE-2026-63267 | LFI and GET SSRF via calcext:data-mappings and csv provider | MEDIUM | 0.11% | Oct 5, 2026 |
| CVE-2026-63266 | Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality | MEDIUM | 0.16% | Oct 5, 2026 |
| CVE-2026-63279 | Out of bounds read in PICT image import | MEDIUM | 0.17% | Sep 22, 2026 |
| CVE-2026-63278 | Package URLs can be used to exfiltrate arbitrary INI file values and environment variables | MEDIUM | 0.15% | Sep 22, 2026 |
| CVE-2026-63276 | Stack buffer overflow in CFF to Type 1 font conversion | MEDIUM | 0.19% | Sep 22, 2026 |
| CVE-2026-63275 | Stack buffer overflow in CFF font hint handling | MEDIUM | 0.17% | Sep 22, 2026 |
| CVE-2026-63274 | Heap buffer overflow in PDF import stream handling | MEDIUM | 0.17% | Sep 22, 2026 |
| CVE-2026-63273 | Heap buffer overflow in PDF import encryption handling | MEDIUM | 0.11% | Sep 22, 2026 |
| CVE-2026-63272 | Heap buffer overflow in WMF text record import | MEDIUM | 0.17% | Sep 22, 2026 |
| CVE-2026-8358 | Heap buffer overflow in spreadsheet tracked-changes import | MEDIUM | 0.17% | Jun 15, 2026 |
| CVE-2026-8357 | Heap buffer overflow in Calc formula compilation | MEDIUM | 0.23% | Jun 15, 2026 |
| CVE-2026-8356 | Stack buffer overflow in PPT presentation import | MEDIUM | 0.17% | Jun 15, 2026 |
| CVE-2026-6047 | Heap buffer overflow in OOXML text box element import | MEDIUM | 0.17% | Jun 15, 2026 |
| CVE-2026-6045 | Heap buffer overflow in EMF+ gradient brush import | MEDIUM | 0.17% | Jun 15, 2026 |
| CVE-2026-6040 | Heap use-after-free in ODF number-format blank-width parsing | MEDIUM | 0.17% | Jun 15, 2026 |
| CVE-2026-6039 | Heap buffer overflow in DXF polyline import | MEDIUM | 0.17% | Jun 15, 2026 |
| CVE-2026-4430 | Heap Buffer Overflow in AgileEngine | MEDIUM | 0.11% | May 7, 2026 |
| CVE-2025-14714 | TCC Bypass via Inherited Permissions in Bundled Interpreter | LOW | 0.14% | Dec 15, 2025 |
| CVE-2025-2866 | PDF signature forgery with adbe.pkcs7.sha1 SubFilter | LOW | 0.12% | Apr 27, 2025 |
| CVE-2021-25635 | Content Manipulation with Certificate Validation Attack | MEDIUM | 0.14% | Mar 21, 2025 |
| CVE-2025-1080 | Macro URL arbitrary script execution | HIGH | 0.30% | Mar 4, 2025 |
Showing 1 to 25 of 56 CVEs