Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A heap buffer overflow vulnerability exists in LibreOffice Calc when importing tracked changes from spreadsheet documents that reuse the same change identifier for different change types. This causes a type confusion where the importer treats one change object as a larger type, leading to out-of-bounds memory writes. The issue affects versions 25.8 and 26.2. The vulnerability has a medium severity rating with a CVSS score of 5.4. No official patch or remediation information is currently available. Join the discussion | CVE Database V5 | 06/15/2026, 16:24:03 UTC Added: 06/15/2026, 18:00:22 UTC |
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting. Join the discussion | CVE Database V5 | 06/15/2026, 16:23:37 UTC Added: 06/15/2026, 18:00:22 UTC |
LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a colour-replacement record. Two fixed-size colour tables were filled from the file, but the write position was not reset between the two passes over the record, so a file whose combined colour counts exceeded the table size wrote past the end of the tables on the stack. In fixed versions the unused second pass is no longer read into those tables. Join the discussion | CVE Database V5 | 06/15/2026, 16:23:06 UTC Added: 06/15/2026, 18:00:22 UTC |
LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's field layout, but it could be a smaller object, so the write landed past the end of the allocation. In fixed versions the type is checked before the write. Join the discussion | CVE Database V5 | 06/15/2026, 16:22:37 UTC Added: 06/15/2026, 18:00:22 UTC |
LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to compute an allocation size, but that multiplication could overflow, so a small buffer was allocated and then filled as if it were large, writing past its end. In fixed versions the blend-point count is checked against the data actually available before allocating. Join the discussion | CVE Database V5 | 06/15/2026, 16:22:16 UTC Added: 06/15/2026, 18:00:22 UTC |
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use. Join the discussion | CVE Database V5 | 06/15/2026, 16:21:53 UTC Added: 06/15/2026, 18:00:22 UTC |
LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point count taken from the file was truncated to a 16-bit value when the point buffer was sized, while the full count was used to fill it, so a polyline whose point count exceeded the 16-bit range was written past the end of the buffer. In fixed versions such oversized polylines are rejected. Join the discussion | CVE Database V5 | 06/15/2026, 16:21:16 UTC Added: 06/15/2026, 18:00:22 UTC |
An out-of-bounds write vulnerability exists in The Document Foundation's LibreOffice when processing crafted OOXML documents with mismatched encryption salt parameters. This affects LibreOffice versions 26.2 before 26.2.3 and 25.8 before 25.8.7. The vulnerability is classified under CWE-787 and has a medium severity with a CVSS 4.0 base score of 5. Join the discussion | CVE Database V5 | 05/07/2026, 07:16:18 UTC Added: 05/07/2026, 07:36:41 UTC |
0 LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1. Join the discussion | CVE Database V5 | 03/04/2025, 20:04:10 UTC Added: 11/03/2025, 19:53:59 UTC |
0 Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be constructed which expanded environmental variables or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. This issue affects LibreOffice: from 24.8 before < 24.8.4. Join the discussion | CVE Database V5 | 01/07/2025, 12:22:32 UTC Added: 11/03/2025, 21:40:23 UTC |
Showing 1 to 10 of 11 results