CVE-2020-13546
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
In SoftMaker Software GmbH SoftMaker Office TextMaker 2021 (revision 1014), a specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon usage of this buffer the application will write outside its bounds resulting in a heap-based buffer overflow. An attacker can entice the victim to open a document to trigger this vulnerability.
En SoftMaker Software GmbH SoftMaker Office TextMaker 2021 (revisión 1014), un documento especialmente diseñado puede causar que el analizador de documentos calcule inapropiadamente una longitud utilizada para asignar un búfer; más adelante, al usar este búfer, la aplicación escribirá fuera de sus límites resultando en un desbordamiento del búfer en la región heap de la memoria. Un atacante puede atraer a la víctima a abrir un documento para desencadenar esta vulnerabilidad
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-05-26 CVE Reserved
- 2021-02-10 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-131: Incorrect Calculation of Buffer Size
- CWE-190: Integer Overflow or Wraparound
- CWE-787: Out-of-bounds Write
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1163 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Softmaker Search vendor "Softmaker" | Office Textmaker 2021 Search vendor "Softmaker" for product "Office Textmaker 2021" | 1014 Search vendor "Softmaker" for product "Office Textmaker 2021" and version "1014" | - |
Affected
|