Search CVE reports


Toggle filters

1 – 10 of 116 results


CVE-2026-63277

Medium priority
Needs evaluation

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-63270

Medium priority
Needs evaluation

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-63269

Medium priority
Needs evaluation

LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist that made GStreamer read the local files and remote URLs it listed while the...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-63268

Medium priority
Needs evaluation

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder of local text files as a database, so opening a document could read a local text...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-63267

Medium priority
Needs evaluation

LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-63266

Medium priority
Needs evaluation

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-63279

Medium priority

Some fixes available 3 of 4

LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation —
Show less packages

CVE-2026-63278

Medium priority

Some fixes available 3 of 4

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation —
Show less packages

CVE-2026-63276

Medium priority

Some fixes available 3 of 4

LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation —
Show less packages

CVE-2026-63275

Medium priority

Some fixes available 3 of 4

LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than...

1 affected package

libreoffice

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libreoffice Fixed Fixed Fixed Needs evaluation —
Show less packages