VYPR

Gnumeric

by GNOME Foundation

CVEs (3)

  • CVE-2013-6836Dec 19, 2013
    risk 0.00cvss epss 0.02

    Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.

  • CVE-2009-0318Jan 28, 2009
    risk 0.00cvss epss 0.00

    Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

  • CVE-2008-0668Feb 11, 2008
    risk 0.00cvss epss 0.05

    The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file containing XLS HLINK opcodes, possibly because of an integer signedness error that leads to…