5
CVSSv2

CVE-2017-14226

Published: 09/09/2017 Updated: 09/11/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

WP1StylesListener.cpp, WP5StylesListener.cpp, and WP42StylesListener.cpp in libwpd 0.10.1 mishandle iterators, which allows remote malicious users to cause a denial of service (heap-based buffer over-read in the WPXTableList class in WPXTable.cpp). This vulnerability can be triggered in LibreOffice prior to 5.3.7. It may lead to suffering a remote attack against a LibreOffice application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libreoffice libreoffice

libwpd libwpd 0.10.1

Vendor Advisories

Debian Bug report logs - #876001 libwpd: CVE-2017-14226 Package: src:libwpd; Maintainer for src:libwpd is Debian LibreOffice Maintainers <debian-openoffice@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 17 Sep 2017 08:51:01 UTC Severity: important Tags: patch, security, upstream ...
WP1StylesListenercpp, WP5StylesListenercpp, and WP42StylesListenercpp in libwpd 0101 mishandle iterators, which allows remote attackers to cause a denial of service (heap-based buffer over-read in the WPXTableList class in WPXTablecpp) This vulnerability can be triggered in LibreOffice before 537 It may lead to suffering a remote attack a ...