10
CVSSv2

CVE-2004-0645

Published: 06/08/2004 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the wvHandleDateTimePicture function in wv library (wvWare) 0.7.4 up to and including 0.7.6 and 1.0.0 allows remote malicious users to execute arbitrary code via a document with a long DateTime field.

Vulnerable Product Search on Vulmon Subscribe to Product

abisource community abiword 2.0.3

wvware wvware 1.0

abisource community abiword 2.0.4

abisource community abiword 2.0.5

wvware wvware 0.7.5

wvware wvware 0.7.6

abisource community abiword 2.0.6

abisource community abiword 2.0.7

wvware wvware 0.7.4

Vendor Advisories

iDEFENSE discovered a buffer overflow in the wv library, used to convert and preview Microsoft Word documents An attacker could create a specially crafted document that could lead wvHtml to execute arbitrary code on the victims machine For the stable distribution (woody) this problem has been fixed in version 071+rvt-2woody3 For the unstable d ...