Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-8358

Опубликовано: 15 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identifier for two different kinds of change. The importer then treated one change object as a different, larger type and wrote past the end of its allocation. In fixed versions records with a duplicate identifier are rejected.

РелизСтатусПримечание
devel

not-affected

4:26.2.4.2-0ubuntu1
esm-infra/focal

needs-triage

jammy

released

1:7.3.7-0ubuntu0.22.04.12
noble

released

4:24.2.7-0ubuntu0.24.04.6
questing

ignored

end of life, was needs-triage
resolute

released

4:26.2.4.2-0ubuntu0.26.04.2
upstream

released

26.2.4

Показывать по

EPSS

Процентиль: 7%
0.00171
Низкий

Связанные уязвимости

CVSS3: 6.6
redhat
около 2 месяцев назад

LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identifier for two different kinds of change. The importer then treated one change object as a different, larger type and wrote past the end of its allocation. In fixed versions records with a duplicate identifier are rejected.

nvd
около 2 месяцев назад

LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identifier for two different kinds of change. The importer then treated one change object as a different, larger type and wrote past the end of its allocation. In fixed versions records with a duplicate identifier are rejected.

debian
около 2 месяцев назад

LibreOffice Calc can import tracked changes from a spreadsheet documen ...

github
около 2 месяцев назад

LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identifier for two different kinds of change. The importer then treated one change object as a different, larger type and wrote past the end of its allocation. In fixed versions records with a duplicate identifier are rejected.

CVSS3: 6.6
fstec
около 2 месяцев назад

Уязвимость пакета офисных программ LibreOffice, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 7%
0.00171
Низкий