4.3
CVSSv2

CVE-2013-6836

Published: 19/12/2013 Updated: 31/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric prior to 1.12.9 allows remote malicious users to cause a denial of service (crash) via a crafted xls file with a crafted length value.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gnumeric

gnome gnumeric 1.12.7

gnome gnumeric 1.12.0

gnome gnumeric 1.12.4

gnome gnumeric 1.12.3

gnome gnumeric 1.12.6

gnome gnumeric 1.12.5

gnome gnumeric 1.12.2

gnome gnumeric 1.12.1