Vulnerabilities > Hancom > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-02-16 CVE-2021-21958 Out-of-bounds Write vulnerability in Hancom Office 2020 11.0.0.2353
A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353.
network
hancom CWE-787
6.8
2021-11-22 CVE-2020-7882 Path Traversal vulnerability in Hancom Anysign4Pc 1.1.1.0/1.1.2.6/1.1.2.7
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files.
network
low complexity
hancom CWE-22
6.4
2020-03-19 CVE-2019-16338 Use After Free vulnerability in Hancom Office NEO 9.6.1.7634
The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.
network
hancom CWE-416
6.8
2020-03-19 CVE-2019-16337 Use After Free vulnerability in Hancom Office NEO 9.6.1.9403
The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.
network
hancom CWE-416
6.8
2018-12-21 CVE-2018-5201 Out-of-bounds Write vulnerability in Hancom products
Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Office 2010 8.5.8.1724 and earlier versions have a heap overflow vulnerability when handling Compound File in document.
network
hancom CWE-787
4.3
2017-07-25 CVE-2015-6585 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hancom Hangul Word Processor 2014
hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type confusion" via an HWPX file containing a crafted para text tag.
network
hancom CWE-119
6.8
2017-05-24 CVE-2017-2819 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hancom Hangul Word Processor and Thinkfree Office NEO
An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) of Hancom Thinkfree Office NEO 9.6.1.4902.
network
hancom CWE-119
6.8
2017-04-20 CVE-2016-4293 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hancom Office 2014 9.1.0.2176
Multiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle functions in Hancom Office 2014 VP allow remote attackers to execute arbitrary code via a crafted Hangul Hcell Document (.cell) file.
network
hancom CWE-119
6.8
2017-01-06 CVE-2016-4298 Integer Overflow or Wraparound vulnerability in Hancom Office 2014 9.1.0.2176
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate space for a list of elements using a length from the file.
network
hancom CWE-190
6.8
2017-01-06 CVE-2016-4296 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hancom Office 2014 9.1.0.2176
When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end of the string and write a null terminator after it.
network
hancom CWE-119
6.8