Hancom records
25 published records for vendor hancom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-416 Use After Free4
- CWE-190 Integer Overflow or Wraparound3
- CWE-189 Numeric Errors2
- CWE-121 Stack-based Buffer Overflow2
- CWE-124 Buffer Underwrite ('Buffer Underflow')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
25 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-5195No exploit | Hancom NEO versions 9.6.1.5183 and earlier have a buffer Overflow vulnerability that leads remote attackers to execute arbitrary commands whhancom · thinkfree office neo · CWE-119 | Critical9.8 | — | 2.6% | Jan 17, 2018 |
38Monitor | CVE-2012-1206No exploit | Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (hancom · hancom office 2010 se · CWE-189 | Critical9.3 | — | 4.8% | Feb 24, 2012 |
36Monitor | CVE-2020-7882Proof of concept | anySign directory traversal vulnerabilityhancom · anysign4pc · CWE-24 | Critical9.1 | — | 1.3% | Nov 22, 2021 |
35Monitor | CVE-2023-51598No exploit | Hancom Office Word DOC File Parsing Use-After-Free Remote Code Execution Vulnerabilityhancom · office word · CWE-416 | High8.8 | — | 0.7% | May 2, 2024 |
35Monitor | CVE-2023-40250No exploit | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.Thishancom · hcell · CWE-120 | High8.8 | — | 0.6% | Jan 11, 2024 |
32Monitor | CVE-2013-7420Proof of concept | Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute in a TEXTART Xhancom · hancom office 2010 se · CWE-119 | High7.5 | — | 7.0% | Jan 12, 2015 |
32Monitor | CVE-2016-4293No exploit | Multiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle functions in Hancom Office 2hancom · hancom office 2014 · CWE-119 | High7.8 | — | 3.6% | Apr 20, 2017 |
32Monitor | CVE-2015-6585No exploit | hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type cohancom · hangul word processor · CWE-119 | High7.8 | — | 2.5% | Jul 25, 2017 |
32Monitor | CVE-2016-4294No exploit | When opening a Hangul Hcell Document (.cell) and processing a property record within the Workbook stream, Hancom Office 2014 will attempt tohancom · hancom office 2014 · CWE-119 | High7.8 | — | 2.4% | Jan 6, 2017 |
32Monitor | CVE-2016-4298No exploit | When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate spachancom · hancom office 2014 · CWE-190 | High7.8 | — | 2.3% | Jan 6, 2017 |
32Monitor | CVE-2016-4295No exploit | When opening a Hangul Hcell Document (.cell) and processing a particular record within the Workbook stream, an index miscalculation leading hancom · hancom office 2014 · CWE-119 | High7.8 | — | 2.2% | Jan 6, 2017 |
32Monitor | CVE-2016-4296No exploit | When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for ahancom · hancom office 2014 · CWE-119 | High7.8 | — | 2.2% | Jan 6, 2017 |
32Monitor | CVE-2016-4290No exploit | When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate spachancom · hancom office 2014 · CWE-190 | High7.8 | — | 2.1% | Jan 6, 2017 |
32Monitor | CVE-2016-4291No exploit | When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a field from the strhancom · hancom office 2014 · CWE-190 | High7.8 | — | 2.1% | Jan 6, 2017 |
32Monitor | CVE-2016-4292No exploit | When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a static size to allhancom · hancom office 2014 · CWE-119 | High7.8 | — | 2.1% | Jan 6, 2017 |
31Monitor | CVE-2015-2810No exploit | Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWohancom · hanword viewer 2007 · CWE-189 | High7.5 | — | 2.3% | May 15, 2015 |
31Monitor | CVE-2017-2819No exploit | An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) of Hancom Thinkfree Office NEO hancom · hangul word processor · CWE-119 | High7.8 | — | 1.7% | May 24, 2017 |
31Monitor | CVE-2019-16337No exploit | The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.hancom · hancom office neo · CWE-416 | High7.8 | — | 1.1% | Mar 19, 2020 |
31Monitor | CVE-2021-21958No exploit | A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353.hancom · hancom office 2020 · CWE-122 | High7.8 | — | 1.1% | Feb 16, 2022 |
31Monitor | CVE-2019-16338No exploit | The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.hancom · hancom office neo · CWE-416 | High7.8 | — | 1.0% | Mar 19, 2020 |
31Monitor | CVE-2023-32541No exploit | A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520.hancom · hancom office 2020 · CWE-416 | High7.8 | — | 0.7% | Sep 27, 2023 |
31Monitor | CVE-2022-33896No exploit | A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files.hancom · hancom office 2020 · CWE-124 | High7.8 | — | 0.5% | Oct 7, 2022 |
31Monitor | CVE-2023-50235No exploit | Hancom Office Show PPT File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerabilityhancom · office show · CWE-121 | High7.8 | — | 0.4% | May 2, 2024 |
31Monitor | CVE-2023-50234No exploit | Hancom Office Cell XLS File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerabilityhancom · office cell · CWE-121 | High7.8 | — | 0.3% | May 2, 2024 |
22Monitor | CVE-2018-5201No exploit | Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Offhancom · hancom office 2010 · CWE-787 | Medium5.5 | — | 0.7% | Dec 21, 2018 |
- CVE-2018-519540Plan
Hancom NEO versions 9.6.1.5183 and earlier have a buffer Overflow vulnerability that leads remote attackers to execute arbitrary commands wh
CriticalCVSS 9.8No exploitEPSS 3%hancom · thinkfree office neoJan 17, 2018
- CVE-2012-120638Monitor
Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (
CriticalCVSS 9.3No exploitEPSS 5%hancom · hancom office 2010 seFeb 24, 2012
- CVE-2020-788236Monitor
anySign directory traversal vulnerability
CriticalCVSS 9.1Proof of conceptEPSS 1%hancom · anysign4pcNov 22, 2021
- CVE-2023-5159835Monitor
Hancom Office Word DOC File Parsing Use-After-Free Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%hancom · office wordMay 2, 2024
- CVE-2023-4025035Monitor
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.This
HighCVSS 8.8No exploitEPSS 1%hancom · hcellJan 11, 2024
- CVE-2013-742032Monitor
Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute in a TEXTART X
HighCVSS 7.5Proof of conceptEPSS 7%hancom · hancom office 2010 seJan 12, 2015
- CVE-2016-429332Monitor
Multiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle functions in Hancom Office 2
HighCVSS 7.8No exploitEPSS 4%hancom · hancom office 2014Apr 20, 2017
- CVE-2015-658532Monitor
hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type co
HighCVSS 7.8No exploitEPSS 2%hancom · hangul word processorJul 25, 2017
- CVE-2016-429432Monitor
When opening a Hangul Hcell Document (.cell) and processing a property record within the Workbook stream, Hancom Office 2014 will attempt to
HighCVSS 7.8No exploitEPSS 2%hancom · hancom office 2014Jan 6, 2017
- CVE-2016-429832Monitor
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate spac
HighCVSS 7.8No exploitEPSS 2%hancom · hancom office 2014Jan 6, 2017
- CVE-2016-429532Monitor
When opening a Hangul Hcell Document (.cell) and processing a particular record within the Workbook stream, an index miscalculation leading
HighCVSS 7.8No exploitEPSS 2%hancom · hancom office 2014Jan 6, 2017
- CVE-2016-429632Monitor
When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for a
HighCVSS 7.8No exploitEPSS 2%hancom · hancom office 2014Jan 6, 2017
- CVE-2016-429032Monitor
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate spac
HighCVSS 7.8No exploitEPSS 2%hancom · hancom office 2014Jan 6, 2017
- CVE-2016-429132Monitor
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a field from the str
HighCVSS 7.8No exploitEPSS 2%hancom · hancom office 2014Jan 6, 2017
- CVE-2016-429232Monitor
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a static size to all
HighCVSS 7.8No exploitEPSS 2%hancom · hancom office 2014Jan 6, 2017
- CVE-2015-281031Monitor
Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWo
HighCVSS 7.5No exploitEPSS 2%hancom · hanword viewer 2007May 15, 2015
- CVE-2017-281931Monitor
An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) of Hancom Thinkfree Office NEO
HighCVSS 7.8No exploitEPSS 2%hancom · hangul word processorMay 24, 2017
- CVE-2019-1633731Monitor
The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.
HighCVSS 7.8No exploitEPSS 1%hancom · hancom office neoMar 19, 2020
- CVE-2021-2195831Monitor
A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353.
HighCVSS 7.8No exploitEPSS 1%hancom · hancom office 2020Feb 16, 2022
- CVE-2019-1633831Monitor
The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.
HighCVSS 7.8No exploitEPSS 1%hancom · hancom office neoMar 19, 2020
- CVE-2023-3254131Monitor
A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520.
HighCVSS 7.8No exploitEPSS 1%hancom · hancom office 2020Sep 27, 2023
- CVE-2022-3389631Monitor
A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files.
HighCVSS 7.8No exploitEPSS 1%hancom · hancom office 2020Oct 7, 2022
- CVE-2023-5023531Monitor
Hancom Office Show PPT File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 0%hancom · office showMay 2, 2024
- CVE-2023-5023431Monitor
Hancom Office Cell XLS File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 0%hancom · office cellMay 2, 2024
- CVE-2018-520122Monitor
Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Off
MediumCVSS 5.5No exploitEPSS 1%hancom · hancom office 2010Dec 21, 2018