Lucene search

K
cve[email protected]CVE-2015-2810
HistoryMay 15, 2015 - 10:59 p.m.

CVE-2015-2810

2015-05-1522:59:00
CWE-189
web.nvd.nist.gov
22
cve-2015-2810
integer overflow
hancom office
hanword
denial of service
heap corruption
security vulnerability
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

High

0.028 Low

EPSS

Percentile

90.8%

Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWord Viewer 2007 and Viewer 2010 8.5.6.1158, and HwpViewer 2014 VP 9.1.0.2186, allows remote attackers to cause a denial of service (crash) and possibly “influence the program’s execution flow” via a document with a large paragraph size, which triggers heap corruption.

Affected configurations

NVD
Node
hancomhanword_viewer_2007
OR
hancomhanword_viewer_2010Match8.5.6.1158
OR
hancomhwp_2014Range9.1.0.2342
OR
hancomhwpviewer_2014Match9.1.0.2186

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

High

0.028 Low

EPSS

Percentile

90.8%

Related for CVE-2015-2810