Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were read separately from the file and were not required to agree, so drawing the text walked the advance array by character position and ran past its end when the array was the shorter of the two. In fixed versions an advance array shorter than its text is ignored. | |
| Title | Heap buffer overflow in WMF text record import | |
| Weaknesses | CWE-125 CWE-787 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Document Fdn.
Published:
Updated: 2026-09-22T12:28:29.813Z
Reserved: 2026-07-16T08:17:05.511Z
Link: CVE-2026-63272
Updated: 2026-09-22T12:28:21.895Z
Status : Received
Published: 2026-09-22T12:17:11.853
Modified: 2026-09-22T13:17:10.180
Link: CVE-2026-63272
No data.
OpenCVE Enrichment
Updated: 2026-09-22T13:00:14Z
