Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

libreoffice — Vulnerabilities & Security Advisories 52

All 52 CVE vulnerabilities found in libreoffice, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the LibreOffice desktop suite, categorized by specific weakness types. It collects data covering memory corruption, input validation flaws, and privilege escalation issues, spanning advisories from 2006 through the present. Readers can use this section to track the vendor’s security advisories, analyze the prevalence of particular weakness classes, or review the complete vulnerability history associated with the LibreOffice product line. The dataset highlights recurring patterns in code execution risks and denial-of-service conditions found across various release cycles.

Vendor: [UNKNOWN]

CVE ID Title CVSS Severity Published
CVE-2026-63279 Out of bounds read in PICT image import CWE-125 5.4 Medium 2026-09-22
CVE-2026-63278 Package URLs can be used to exfiltrate arbitrary INI file values and environment variables CWE-200 6.7 Medium 2026-09-22
CVE-2026-63276 Stack buffer overflow in CFF to Type 1 font conversion CWE-787 5.4 Medium 2026-09-22
CVE-2026-63275 Stack buffer overflow in CFF font hint handling CWE-787 5.4 Medium 2026-09-22
CVE-2026-63274 Heap buffer overflow in PDF import stream handling CWE-787 5.4 Medium 2026-09-22
CVE-2026-63273 Heap buffer overflow in PDF import encryption handling CWE-787 5.4 Medium 2026-09-22
CVE-2026-63272 Heap buffer overflow in WMF text record import CWE-787 5.4 Medium 2026-09-22
CVE-2026-8358 Heap buffer overflow in spreadsheet tracked-changes import CWE-843 - - 2026-06-15
CVE-2026-8357 Heap buffer overflow in Calc formula compilation CWE-787 5.4 Medium 2026-06-15
CVE-2026-8356 Stack buffer overflow in PPT presentation import CWE-787 - - 2026-06-15
CVE-2026-6047 Heap buffer overflow in OOXML text box element import CWE-787 - - 2026-06-15
CVE-2026-6045 Heap buffer overflow in EMF+ gradient brush import CWE-787 5.4 Medium 2026-06-15
CVE-2026-6040 Heap use-after-free in ODF number-format blank-width parsing CWE-416 5.4 Medium 2026-06-15
CVE-2026-6039 Heap buffer overflow in DXF polyline import CWE-787 - - 2026-06-15
CVE-2026-4430 Heap Buffer Overflow in AgileEngine CWE-787 7.8AI High AI 2026-05-07
CVE-2025-14714 TCC Bypass via Inherited Permissions in Bundled Interpreter CWE-288 9.8AI Critical AI 2025-12-15
CVE-2025-2866 PDF signature forgery with adbe.pkcs7.sha1 SubFilter CWE-347 6.5 - 2025-04-27
CVE-2021-25635 Content Manipulation with Certificate Validation Attack CWE-295 7.5 - 2025-03-21
CVE-2025-1080 Macro URL arbitrary script execution CWE-20 8.8 - 2025-03-04
CVE-2025-0514 Executable hyperlink Windows path targets executed unconditionally on activation CWE-20 6.5 - 2025-02-25
CVE-2024-12426 URL fetching can be used to exfiltrate arbitrary INI file values and environment variables CWE-200 6.5 - 2025-01-07
CVE-2024-12425 Path traversal leading to arbitrary .ttf file write CWE-22 6.2 - 2025-01-07
CVE-2024-7788 Signatures in "repair mode" should not be trusted CWE-347 7.8 High 2024-09-17
CVE-2024-6472 Ability to trust not validated macro signatures removed in high security mode CWE-295 7.8 High 2024-08-05
CVE-2024-5261 TLS certificate are not properly verified when utilizing LibreOfficeKit CWE-295 9.1AI Critical AI 2024-06-25
CVE-2024-3044 Graphic on-click binding allows unchecked script execution CWE-356 7.1 - 2024-05-14
CVE-2023-6186 Link targets allow arbitrary script execution 8.3 High 2023-12-11
CVE-2023-6185 Improper input validation enabling arbitrary Gstreamer pipeline injection 8.3 High 2023-12-11
CVE-2023-1183 Arbitrary file write CWE-20 5.0 Medium 2023-07-10
CVE-2023-0950 Array Index UnderFlow in Calc Formula Parsing CWE-129 8.8 - 2023-05-25

All 52 known CVE vulnerabilities affecting libreoffice with full Chinese analysis, references, and POCs where available.