Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size key buffer without being checked against it, so a length larger than that buffer wrote past its end. In fixed versions a declared key length larger than the buffer is rejected. | |
| Title | Heap buffer overflow in PDF import encryption handling | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Document Fdn.
Published:
Updated: 2026-09-22T12:27:46.334Z
Reserved: 2026-07-16T08:17:05.512Z
Link: CVE-2026-63273
Updated: 2026-09-22T12:27:38.705Z
Status : Received
Published: 2026-09-22T12:17:13.007
Modified: 2026-09-22T13:17:10.300
Link: CVE-2026-63273
No data.
OpenCVE Enrichment
Updated: 2026-09-22T12:30:07Z
-
CWE-787
Out-of-bounds Write