Search CVE reports


Toggle filters

11 – 20 of 110 results


CVE-2026-6047

Medium priority
Fixed

LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-6045

Medium priority

Some fixes available 3 of 5

LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to compute an...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2026-6040

Medium priority

Some fixes available 2 of 3

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Not affected Not affected
Show less packages

CVE-2026-6039

Medium priority

Some fixes available 3 of 5

LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point count taken from the file was truncated to a 16-bit value when the point buffer was...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2026-4430

Medium priority

Some fixes available 4 of 5

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2025-14714

Medium priority
Not affected

An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Not affected Not affected Not affected
Show less packages

CVE-2025-2866

Medium priority
Fixed

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed
Show less packages

CVE-2021-25635

Medium priority
Not affected

An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the target, then modify it to change the signature algorithm to an invalid (or unknown...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Not affected Not affected Not affected
Show less packages

CVE-2025-1080

Medium priority
Fixed

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed
Show less packages

CVE-2025-0514

Medium priority
Not affected

Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditionally on activation.This issue affects LibreOffice: from 24.8 before < 24.8.5.

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Not affected Not affected Not affected
Show less packages