Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-13545

Опубликовано: 06 янв. 2021
Источник: nvd
CVSS3: 8.8
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

An exploitable signed conversion vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon usage of this buffer the application will write outside its bounds resulting in a heap-based memory corruption. An attacker can entice the victim to open a document to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:softmaker:softmaker_office:2021:*:*:*:*:*:*:*

EPSS

Процентиль: 60%
0.00396
Низкий

8.8 High

CVSS3

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-196
CWE-681

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

An exploitable signed conversion vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon usage of this buffer the application will write outside its bounds resulting in a heap-based memory corruption. An attacker can entice the victim to open a document to trigger this vulnerability.

EPSS

Процентиль: 60%
0.00396
Низкий

8.8 High

CVSS3

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-196
CWE-681