Записи Hancom
25 опубликованных записей вендора hancom.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-416 Use After Free4
- CWE-190 Integer Overflow or Wraparound3
- CWE-189 Numeric Errors2
- CWE-121 Stack-based Buffer Overflow2
- CWE-124 Buffer Underwrite ('Buffer Underflow')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
25 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-5195Эксплойта нет | Hancom NEO versions 9.6.1.5183 and earlier have a buffer Overflow vulnerability that leads remote attackers to execute arbitrary commands whhancom · thinkfree office neo · CWE-119 | Критическая9,8 | — | 2,6 % | 17 янв. 2018 г. |
38Наблюдать | CVE-2012-1206Эксплойта нет | Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (hancom · hancom office 2010 se · CWE-189 | Критическая9,3 | — | 4,8 % | 24 февр. 2012 г. |
36Наблюдать | CVE-2020-7882Proof of concept | anySign directory traversal vulnerabilityhancom · anysign4pc · CWE-24 | Критическая9,1 | — | 1,3 % | 22 нояб. 2021 г. |
35Наблюдать | CVE-2023-51598Эксплойта нет | Hancom Office Word DOC File Parsing Use-After-Free Remote Code Execution Vulnerabilityhancom · office word · CWE-416 | Высокая8,8 | — | 0,7 % | 2 мая 2024 г. |
35Наблюдать | CVE-2023-40250Эксплойта нет | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.Thishancom · hcell · CWE-120 | Высокая8,8 | — | 0,6 % | 11 янв. 2024 г. |
32Наблюдать | CVE-2013-7420Proof of concept | Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute in a TEXTART Xhancom · hancom office 2010 se · CWE-119 | Высокая7,5 | — | 7,0 % | 12 янв. 2015 г. |
32Наблюдать | CVE-2016-4293Эксплойта нет | Multiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle functions in Hancom Office 2hancom · hancom office 2014 · CWE-119 | Высокая7,8 | — | 3,6 % | 20 апр. 2017 г. |
32Наблюдать | CVE-2015-6585Эксплойта нет | hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type cohancom · hangul word processor · CWE-119 | Высокая7,8 | — | 2,5 % | 25 июл. 2017 г. |
32Наблюдать | CVE-2016-4294Эксплойта нет | When opening a Hangul Hcell Document (.cell) and processing a property record within the Workbook stream, Hancom Office 2014 will attempt tohancom · hancom office 2014 · CWE-119 | Высокая7,8 | — | 2,4 % | 6 янв. 2017 г. |
32Наблюдать | CVE-2016-4298Эксплойта нет | When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate spachancom · hancom office 2014 · CWE-190 | Высокая7,8 | — | 2,3 % | 6 янв. 2017 г. |
32Наблюдать | CVE-2016-4295Эксплойта нет | When opening a Hangul Hcell Document (.cell) and processing a particular record within the Workbook stream, an index miscalculation leading hancom · hancom office 2014 · CWE-119 | Высокая7,8 | — | 2,2 % | 6 янв. 2017 г. |
32Наблюдать | CVE-2016-4296Эксплойта нет | When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for ahancom · hancom office 2014 · CWE-119 | Высокая7,8 | — | 2,2 % | 6 янв. 2017 г. |
32Наблюдать | CVE-2016-4290Эксплойта нет | When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate spachancom · hancom office 2014 · CWE-190 | Высокая7,8 | — | 2,1 % | 6 янв. 2017 г. |
32Наблюдать | CVE-2016-4291Эксплойта нет | When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a field from the strhancom · hancom office 2014 · CWE-190 | Высокая7,8 | — | 2,1 % | 6 янв. 2017 г. |
32Наблюдать | CVE-2016-4292Эксплойта нет | When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a static size to allhancom · hancom office 2014 · CWE-119 | Высокая7,8 | — | 2,1 % | 6 янв. 2017 г. |
31Наблюдать | CVE-2015-2810Эксплойта нет | Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWohancom · hanword viewer 2007 · CWE-189 | Высокая7,5 | — | 2,3 % | 15 мая 2015 г. |
31Наблюдать | CVE-2017-2819Эксплойта нет | An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) of Hancom Thinkfree Office NEO hancom · hangul word processor · CWE-119 | Высокая7,8 | — | 1,7 % | 24 мая 2017 г. |
31Наблюдать | CVE-2019-16337Эксплойта нет | The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.hancom · hancom office neo · CWE-416 | Высокая7,8 | — | 1,1 % | 19 мар. 2020 г. |
31Наблюдать | CVE-2021-21958Эксплойта нет | A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353.hancom · hancom office 2020 · CWE-122 | Высокая7,8 | — | 1,1 % | 16 февр. 2022 г. |
31Наблюдать | CVE-2019-16338Эксплойта нет | The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.hancom · hancom office neo · CWE-416 | Высокая7,8 | — | 1,0 % | 19 мар. 2020 г. |
31Наблюдать | CVE-2023-32541Эксплойта нет | A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520.hancom · hancom office 2020 · CWE-416 | Высокая7,8 | — | 0,7 % | 27 сент. 2023 г. |
31Наблюдать | CVE-2022-33896Эксплойта нет | A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files.hancom · hancom office 2020 · CWE-124 | Высокая7,8 | — | 0,5 % | 7 окт. 2022 г. |
31Наблюдать | CVE-2023-50235Эксплойта нет | Hancom Office Show PPT File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerabilityhancom · office show · CWE-121 | Высокая7,8 | — | 0,4 % | 2 мая 2024 г. |
31Наблюдать | CVE-2023-50234Эксплойта нет | Hancom Office Cell XLS File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerabilityhancom · office cell · CWE-121 | Высокая7,8 | — | 0,3 % | 2 мая 2024 г. |
22Наблюдать | CVE-2018-5201Эксплойта нет | Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Offhancom · hancom office 2010 · CWE-787 | Средняя5,5 | — | 0,7 % | 21 дек. 2018 г. |
- CVE-2018-519540В плане
Hancom NEO versions 9.6.1.5183 and earlier have a buffer Overflow vulnerability that leads remote attackers to execute arbitrary commands wh
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %hancom · thinkfree office neo17 янв. 2018 г.
- CVE-2012-120638Наблюдать
Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %hancom · hancom office 2010 se24 февр. 2012 г.
- CVE-2020-788236Наблюдать
anySign directory traversal vulnerability
КритическаяCVSS 9,1Proof of conceptEPSS 1 %hancom · anysign4pc22 нояб. 2021 г.
- CVE-2023-5159835Наблюдать
Hancom Office Word DOC File Parsing Use-After-Free Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hancom · office word2 мая 2024 г.
- CVE-2023-4025035Наблюдать
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.This
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hancom · hcell11 янв. 2024 г.
- CVE-2013-742032Наблюдать
Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute in a TEXTART X
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %hancom · hancom office 2010 se12 янв. 2015 г.
- CVE-2016-429332Наблюдать
Multiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle functions in Hancom Office 2
ВысокаяCVSS 7,8Эксплойта нетEPSS 4 %hancom · hancom office 201420 апр. 2017 г.
- CVE-2015-658532Наблюдать
hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type co
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %hancom · hangul word processor25 июл. 2017 г.
- CVE-2016-429432Наблюдать
When opening a Hangul Hcell Document (.cell) and processing a property record within the Workbook stream, Hancom Office 2014 will attempt to
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %hancom · hancom office 20146 янв. 2017 г.
- CVE-2016-429832Наблюдать
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate spac
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %hancom · hancom office 20146 янв. 2017 г.
- CVE-2016-429532Наблюдать
When opening a Hangul Hcell Document (.cell) and processing a particular record within the Workbook stream, an index miscalculation leading
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %hancom · hancom office 20146 янв. 2017 г.
- CVE-2016-429632Наблюдать
When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for a
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %hancom · hancom office 20146 янв. 2017 г.
- CVE-2016-429032Наблюдать
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate spac
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %hancom · hancom office 20146 янв. 2017 г.
- CVE-2016-429132Наблюдать
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a field from the str
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %hancom · hancom office 20146 янв. 2017 г.
- CVE-2016-429232Наблюдать
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a static size to all
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %hancom · hancom office 20146 янв. 2017 г.
- CVE-2015-281031Наблюдать
Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWo
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %hancom · hanword viewer 200715 мая 2015 г.
- CVE-2017-281931Наблюдать
An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) of Hancom Thinkfree Office NEO
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %hancom · hangul word processor24 мая 2017 г.
- CVE-2019-1633731Наблюдать
The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %hancom · hancom office neo19 мар. 2020 г.
- CVE-2021-2195831Наблюдать
A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %hancom · hancom office 202016 февр. 2022 г.
- CVE-2019-1633831Наблюдать
The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %hancom · hancom office neo19 мар. 2020 г.
- CVE-2023-3254131Наблюдать
A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %hancom · hancom office 202027 сент. 2023 г.
- CVE-2022-3389631Наблюдать
A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %hancom · hancom office 20207 окт. 2022 г.
- CVE-2023-5023531Наблюдать
Hancom Office Show PPT File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %hancom · office show2 мая 2024 г.
- CVE-2023-5023431Наблюдать
Hancom Office Cell XLS File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %hancom · office cell2 мая 2024 г.
- CVE-2018-520122Наблюдать
Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Off
СредняяCVSS 5,5Эксплойта нетEPSS 1 %hancom · hancom office 201021 дек. 2018 г.