5.1
CVSSv2

CVE-2006-4513

Published: 28/10/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple integer overflows in the WV library in wvWare (formerly mswordview) prior to 1.2.3, as used by AbiWord, KWord, and possibly other products, allow user-assisted remote malicious users to execute arbitrary code via a crafted Microsoft Word (DOC) file that produces (1) large LFO clfolvl values in the wvGetLFO_records function or (2) a large LFO nolfo value in the wvGetFLO_PLF function.

Vulnerable Product Search on Vulmon Subscribe to Product

wvware wvware

Vendor Advisories

An integer overflow was discovered in the DOC file parser of the wv library By tricking a user into opening a specially crafted MSWord (DOC) file, remote attackers could execute arbitrary code with the user’s privileges ...