7.5

CVE-2015-2810

Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWord Viewer 2007 and Viewer 2010 8.5.6.1158, and HwpViewer 2014 VP 9.1.0.2186, allows remote attackers to cause a denial of service (crash) and possibly "influence the program's execution flow" via a document with a large paragraph size, which triggers heap corruption.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hancom ≫ Hanword Viewer 2010 Version 8.5.6.1158
Hancom ≫ Hwp 2014 Version <= 9.1.0.2342
Hancom ≫ Hwpviewer 2014 Version 9.1.0.2186
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.31% 0.811
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://seclists.org/bugtraq/2015/Apr/89
http://www.securityfocus.com/bid/74153