Vulnerability Report

CVE-2008-0668

Title: Gnome Gnumeric RCE

Memory Corruption

Proof Of Concept

No public PoC currently indexed for CVE-2008-0668.

CWE Category CWE-189
Published Date Feb 11, 2008
Modified Date Jun 16, 2026
Exploit Status Not Found
Score 9.3 CVSS v2.0
Exploit Probability (EPSS)
4.98%

Vulnerability Summary

CVE-2008-0668: The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file containing XLS HLINK opcodes, possibly because of an integer signedness error that leads to an integer overflow. NOTE: some of these details are obtained from third party information.

Impacted Vendors

Reference Links

http://bugs.gentoo.org/show_bug.cgi?id=208356 http://bugzilla.gnome.org/show_bug.cgi?id=505330 http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00001.html http://secunia.com/advisories/28725/ http://secunia.com/advisories/28799 http://secunia.com/advisories/28948 http://secunia.com/advisories/29702 http://secunia.com/advisories/29896 http://secunia.com/advisories/31339 http://security.gentoo.org/glsa/glsa-200802-05.xml http://www.debian.org/security/2008/dsa-1546 http://www.gnome.org/projects/gnumeric/announcements/1.8/gnumeric-1.8.1.shtml http://www.mandriva.com/security/advisories?name=MDVSA-2008:056 http://www.securityfocus.com/bid/27536 http://www.ubuntu.com/usn/usn-604-1 http://www.vupen.com/english/advisories/2008/0462 https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00114.html https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00227.html http://bugs.gentoo.org/show_bug.cgi?id=208356 http://bugzilla.gnome.org/show_bug.cgi?id=505330 http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00001.html http://secunia.com/advisories/28725/ http://secunia.com/advisories/28799 http://secunia.com/advisories/28948 http://secunia.com/advisories/29702 http://secunia.com/advisories/29896 http://secunia.com/advisories/31339 http://security.gentoo.org/glsa/glsa-200802-05.xml http://www.debian.org/security/2008/dsa-1546 http://www.gnome.org/projects/gnumeric/announcements/1.8/gnumeric-1.8.1.shtml http://www.mandriva.com/security/advisories?name=MDVSA-2008:056 http://www.securityfocus.com/bid/27536 http://www.ubuntu.com/usn/usn-604-1 http://www.vupen.com/english/advisories/2008/0462 https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00114.html https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00227.html
CVSS v2.0
Source Entity [email protected]
Severity HIGH
9.3
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:M/Au:N/C:C/I:C/A:C

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2008-0668 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected Stack

No specific products linked.