// For flags

CVE-2013-6836

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.

Desbordamiento de buffer basado en memoria dinámica en la función ms_escher_get_data en plugins/excel/ms-escher.c en GNOME Office Gnumeric anteriores a 1.12.9 permite a atacantes remotos causar denegación de servicio (caída) a través de un fichero XML manipulado con un valor "length" manipulado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-11-20 CVE Reserved
  • 2013-12-19 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • 2024-09-05 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Gnome
Search vendor "Gnome"
Gnumeric
Search vendor "Gnome" for product "Gnumeric"
<= 1.12.8
Search vendor "Gnome" for product "Gnumeric" and version " <= 1.12.8"
-
Affected
Gnome
Search vendor "Gnome"
Gnumeric
Search vendor "Gnome" for product "Gnumeric"
1.12.0
Search vendor "Gnome" for product "Gnumeric" and version "1.12.0"
-
Affected
Gnome
Search vendor "Gnome"
Gnumeric
Search vendor "Gnome" for product "Gnumeric"
1.12.1
Search vendor "Gnome" for product "Gnumeric" and version "1.12.1"
-
Affected
Gnome
Search vendor "Gnome"
Gnumeric
Search vendor "Gnome" for product "Gnumeric"
1.12.2
Search vendor "Gnome" for product "Gnumeric" and version "1.12.2"
-
Affected
Gnome
Search vendor "Gnome"
Gnumeric
Search vendor "Gnome" for product "Gnumeric"
1.12.3
Search vendor "Gnome" for product "Gnumeric" and version "1.12.3"
-
Affected
Gnome
Search vendor "Gnome"
Gnumeric
Search vendor "Gnome" for product "Gnumeric"
1.12.4
Search vendor "Gnome" for product "Gnumeric" and version "1.12.4"
-
Affected
Gnome
Search vendor "Gnome"
Gnumeric
Search vendor "Gnome" for product "Gnumeric"
1.12.5
Search vendor "Gnome" for product "Gnumeric" and version "1.12.5"
-
Affected
Gnome
Search vendor "Gnome"
Gnumeric
Search vendor "Gnome" for product "Gnumeric"
1.12.6
Search vendor "Gnome" for product "Gnumeric" and version "1.12.6"
-
Affected
Gnome
Search vendor "Gnome"
Gnumeric
Search vendor "Gnome" for product "Gnumeric"
1.12.7
Search vendor "Gnome" for product "Gnumeric" and version "1.12.7"
-
Affected