📦

gnumeric

Vendor: gnome

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 2 Remote Access
Total CVEs 7 Total Indexed
Avg. EPSS 1.88% Exploit Prob.
Latest CVE CVE-2013-6836 Dec 19

Security Vulnerability Index

Page 1 / 1
4.3 CVSS

Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.

EPSS: 1.75%
6.9 CVSS

Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

EPSS: 0.39%
9.3 CVSS

The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file containing XLS HLINK opcodes, possibly because of an integer signedness error that leads to an integer overflow. NOTE: some of these details are obtained from third party information.

EPSS: 4.98%
4.6 CVSS

The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.

EPSS: 0.42%