VYPR
Medium severity5.5NVD Advisory· Published Jan 25, 2018· Updated Jun 17, 2026

CVE-2018-6217

CVE-2018-6217

Description

The WStr::_alloc_iostr_data() function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 allows remote attackers to cause a denial of service (application crash) via a crafted (a) web page, (b) office document, or (c) .rtf file.

Affected products

3
  • Kingsoft/Wps Officellm-fuzzy3 versions
    = 10.1.0.7106 / 10.2.0.5978+ 2 more
    • (no CPE)range: = 10.1.0.7106 / 10.2.0.5978
    • cpe:2.3:a:kingsoftstore:kingsoft_wps_office:10.1.0.7106:*:*:*:*:*:*:*
    • cpe:2.3:a:kingsoftstore:kingsoft_wps_office:10.2.0.5978:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.