CVE detail
CVE-2026-8357
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
13 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:46387access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 15, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:46386access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 15, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:43461access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 15, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:43423access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 15, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:43460access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 15, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:43425access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 15, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:43424access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 15, 2026, 6:16 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8357.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJun 15, 2026, 6:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2488964bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 15, 2026, 6:16 PM - https://access.redhat.com/security/cve/CVE-2026-8357access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 15, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:36832access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 15, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:35839access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 15, 2026, 6:16 PM - https://www.libreoffice.org/about-us/security/advisories/cve-2026-8357www.libreoffice.org
No excerpt available.
Vendor Advisorywww.libreoffice.orgJun 15, 2026, 6:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-65706CVSS 8.5 · High
FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted…
- CVE-2026-65705CVSS 7.3 · High
FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamic…
- CVE-2026-45784CVSS 5.1 · Medium
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly…
- CVE-2026-55827CVSS 7.5 · High
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx option pass desktop stride and hei…
- CVE-2026-7831CVSS 7.6 · High
UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In vncviewer/ClientConnection.cpp, when the server-supplied nam…
- CVE-2026-54696CVSS 3.7 · Low
Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized streamed ob…