Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2026-6040

CVE-2026-6040

Medium
Open
TLP:CLEAR

Heap use-after-free in ODF number-format blank-width parsing

NVD CVE.org
Critical Infrastructure

AI Analysis

No AI analysis yet.

Description

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.

Details

CVSS Score
5.4
EPSS Score
0.11%

1.7th percentile

CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P
Confidence
90%
Published
Jun 15, 2026
Last Modified
Jul 23, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.