Gnumeric
by Gnumeric
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-97222 | Med | 0.36 | 5.5 | — | Sep 25, 2026 | A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can dereference a freed sheet-object component, causing Gnumeric to crash. | ||
| CVE-2009-0318 | 0.00 | — | 0.00 | Jan 28, 2009 | Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983). | |||
| CVE-2008-0668 | 0.00 | — | 0.05 | Feb 11, 2008 | The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file containing XLS HLINK opcodes, possibly because of an integer signedness error that leads to… | |||
| CVE-1999-0719 | 0.00 | — | 0.00 | Aug 5, 1999 | The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code. |
- risk 0.36cvss 5.5epss —
A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can dereference a freed sheet-object component, causing Gnumeric to crash.
- CVE-2009-0318Jan 28, 2009risk 0.00cvss —epss 0.00
Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
- CVE-2008-0668Feb 11, 2008risk 0.00cvss —epss 0.05
The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file containing XLS HLINK opcodes, possibly because of an integer signedness error that leads to…
- CVE-1999-0719Aug 5, 1999risk 0.00cvss —epss 0.00
The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.