Page 3 of 25 results (0.004 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 1

06 Jan 2017 — When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end of the string and write a null terminator after it. If the character is at the very end of the string, the application will mistakenly write the null-byte outside the bounds of its destination. This can result in heap corruption that can lead code execution under the context of the application Cuando se abre un Hangul Hcell Docume... • http://www.securityfocus.com/bid/92327 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 1

06 Jan 2017 — When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate space for a list of elements using a length from the file. When calculating this length, an integer overflow can be made to occur which will cause the buffer to be undersized when the application tries to copy file data into the object containing this structure. This allows one to overwrite contiguous data in the heap which can lead to code-execution under the context of th... • http://www.securityfocus.com/bid/92325 • CWE-190: Integer Overflow or Wraparound •

CVSS: 9.8EPSS: 1%CPEs: 4EXPL: 0

15 Apr 2015 — Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWord Viewer 2007 and Viewer 2010 8.5.6.1158, and HwpViewer 2014 VP 9.1.0.2186, allows remote attackers to cause a denial of service (crash) and possibly "influence the program's execution flow" via a document with a large paragraph size, which triggers heap corruption. Desbordamiento de enteros en la función HwpApp::CHncSDS_Manager en el procesador Hancom Office HanWord, ... • http://seclists.org/bugtraq/2015/Apr/89 • CWE-189: Numeric Errors •

CVSS: 9.8EPSS: 5%CPEs: 1EXPL: 1

12 Jan 2015 — Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute in a TEXTART XML element in an HML file. Desbordamiento de buffer en Hancom Office 2010 SE permite a atacantes remotos ejecutar código arbitrario a través de una cadena larga en el atributo Text en un elemento TEXTART XML en un fichero HML. • https://www.exploit-db.com/exploits/38910 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.3EPSS: 14%CPEs: 1EXPL: 0

20 Feb 2012 — Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (1) JPG image to the ImportGR in the JPG image filter module (HncJpeg10.flt) or (2) PNG image to the PNG image filter module (HncPng10.flt), which triggers a heap-based buffer overflow. Varias vulnerabilidades de desbordamiento de enteros en Hancom Office v2010 SE v8.5.5 permite a atacantes remotos ejecutar código de su elección a través de (1) una imagen JPG demasiado g... • http://osvdb.org/78906 • CWE-189: Numeric Errors •