7.5
CVSSv2

CVE-2012-3455

Published: 20/08/2012 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and previous versions allows remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.

Vulnerable Product Search on Vulmon Subscribe to Product

kde koffice 1.3

kde koffice 1.3.4

kde koffice 1.4.1

kde koffice 1.3.3

kde koffice 1.3.5

kde koffice

kde koffice 1.2.1

kde koffice 1.4.2

kde koffice 1.6.1

kde koffice 1.3.1

kde koffice 1.2

kde koffice 1.4

kde koffice 1.3.2

Vendor Advisories

KOffice could be made to crash or run programs as your login if it opened a specially crafted file ...