{"id":"CVE-2026-63275","published":"2026-09-22T12:17:13.287","lastModified":"2026-09-22T19:09:32.273","description":"LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the array can hold wrote past its end. In fixed versions the hint count is checked against the capacity the array really has.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-787"],"vendors":[],"products":[],"references":[{"url":"https://www.libreoffice.org/about-us/security/advisories/cve-2026-63275","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}