Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-6047

Опубликовано: 15 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's field layout, but it could be a smaller object, so the write landed past the end of the allocation. In fixed versions the type is checked before the write.

РелизСтатусПримечание
devel

not-affected

4:26.2.4.2-0ubuntu1
esm-infra/focal

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

not-affected

code not present
resolute

released

4:26.2.4.2-0ubuntu0.26.04.2
upstream

released

26.2.3,25.8.7

Показывать по

EPSS

Процентиль: 2%
0.0012
Низкий

Связанные уязвимости

CVSS3: 5
redhat
около 2 месяцев назад

LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's field layout, but it could be a smaller object, so the write landed past the end of the allocation. In fixed versions the type is checked before the write.

nvd
около 2 месяцев назад

LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's field layout, but it could be a smaller object, so the write landed past the end of the allocation. In fixed versions the type is checked before the write.

debian
около 2 месяцев назад

LibreOffice can import documents in the OOXML format (DOCX). A heap bu ...

github
около 2 месяцев назад

LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's field layout, but it could be a smaller object, so the write landed past the end of the allocation. In fixed versions the type is checked before the write.

CVSS3: 5
fstec
около 2 месяцев назад

Уязвимость пакета офисных программ LibreOffice, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 2%
0.0012
Низкий