CVE-2026-97222
- EPSS 0.12%
- Veröffentlicht 25.09.2026 13:51:57
- Zuletzt bearbeitet 30.09.2026 19:38:27
A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can dereference a freed sheet-object component, causing Gnumeric to crash.
CVE-2013-6836
- EPSS 1.75%
- Veröffentlicht 19.12.2013 04:24:57
- Zuletzt bearbeitet 29.04.2026 01:13:23
Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.
CVE-2009-0318
- EPSS 0.39%
- Veröffentlicht 28.01.2009 11:30:00
- Zuletzt bearbeitet 16.06.2026 23:04:45
Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv fu...
CVE-2008-0668
- EPSS 4.98%
- Veröffentlicht 11.02.2008 21:00:00
- Zuletzt bearbeitet 16.06.2026 22:50:06
The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file containing XLS HLINK opcodes, possibly because of an integer s...