Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-3456

Опубликовано: 20 авг. 2012
Источник: nvd
CVSS2: 7.5
EPSS Средний

Описание

Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:calligra:calligra:*:*:*:*:*:*:*:*
Версия до 2.4.3 (включая)
cpe:2.3:a:calligra:calligra:2.4:*:*:*:*:*:*:*
cpe:2.3:a:calligra:calligra:2.4:beta2:*:*:*:*:*:*
cpe:2.3:a:calligra:calligra:2.4:beta3:*:*:*:*:*:*
cpe:2.3:a:calligra:calligra:2.4:beta4:*:*:*:*:*:*
cpe:2.3:a:calligra:calligra:2.4:beta6:*:*:*:*:*:*
cpe:2.3:a:calligra:calligra:2.4:beta7:*:*:*:*:*:*
cpe:2.3:a:calligra:calligra:2.4:rc2:*:*:*:*:*:*
cpe:2.3:a:calligra:calligra:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:calligra:calligra:2.4.2:*:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.46505
Средний

7.5 High

CVSS2

Дефекты

CWE-119

Связанные уязвимости

ubuntu
больше 13 лет назад

Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.

debian
больше 13 лет назад

Heap-based buffer overflow in the read function in filters/words/mswor ...

github
больше 3 лет назад

Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.

EPSS

Процентиль: 98%
0.46505
Средний

7.5 High

CVSS2

Дефекты

CWE-119