CVE-2018-5201
Last modified
CVE-2018-5201 is a vulnerability of currently unknown severity. Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Office 2010 8.5.8.1724 and earlier versions have a heap overflow vulnerability when handling Compound File in document. This result in a program crash or denial of service conditions.. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Office 2010 8.5.8.1724 and earlier versions have a heap overflow vulnerability when handling Compound File in document. This result in a program crash or denial of service conditions.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hancom | Hancom Office 2010 | <= 8.5.8.1724 |
| Hancom | Hancom Office 2014 | <= 9.1.1.4540 |
| Hancom | Hancom Office 2018 | <= 10.0.0.8214 |
| Hancom | Hancom Office Neo | <= 9.6.1.10472 |
References
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=30116Patch, Third Party Advisory
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=30116Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5201?
How severe is CVE-2018-5201?
How do I fix CVE-2018-5201?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5195Hancom NEO versions 9.6.1.5183 and earlier have a buffer Ove…
- CVE-2018-5196Alzip 10.76.0.0 and earlier is vulnerable to a stack overflo…8.8
- CVE-2018-5197A vulnerability in the ExtCommon.dll user extension module v…
- CVE-2018-5198In Veraport G3 ALL on MacOS, a race condition when calling t…8.1
- CVE-2018-5199In Veraport G3 ALL on MacOS, due to insufficient domain vali…8.8
- CVE-2018-5200KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overf…7.8
- CVE-2018-5202SKCertService 2.5.5 and earlier contains a vulnerability tha…
- CVE-2018-5203DEXTUploadX5 version Between 1.0.0.0 and 2.2.0.0 contains a …
- CVE-2018-5204ML Report version Between 2.00.000.0000 and 2.18.628.5980 co…
- CVE-2018-5205When using incomplete escape codes, Irssi before 1.0.6 may a…
- CVE-2018-5206When the channel topic is set without specifying a sender, I…
- CVE-2018-5207When using an incomplete variable argument, Irssi before 1.0…
Are you affected by CVE-2018-5201?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
