A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-10 21:17
Updated : 2026-09-15 15:17
NVD link : CVE-2026-79591
Mitre link : CVE-2026-79591
CVE.ORG link : CVE-2026-79591
JSON object : View
Products Affected
No product.
CWE
CWE-122
Heap-based Buffer Overflow
