URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not recognise eve
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| The Document Foundation | LibreOffice | 26.2< < 26.2.5 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The Document Foundation | LibreOffice | 26.2 ~ < 26.2.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63279 | 5.4 MEDIUM | Out of bounds read in PICT image import |
| CVE-2026-63272 | 5.4 MEDIUM | Heap buffer overflow in WMF text record import |
| CVE-2026-63274 | 5.4 MEDIUM | Heap buffer overflow in PDF import stream handling |
| CVE-2026-63273 | 5.4 MEDIUM | Heap buffer overflow in PDF import encryption handling |
| CVE-2026-63276 | 5.4 MEDIUM | Stack buffer overflow in CFF to Type 1 font conversion |
| CVE-2026-63275 | 5.4 MEDIUM | Stack buffer overflow in CFF font hint handling |
No comments yet