Known Vulnerabilities for products from Hancom
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Hancom".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-32541 json | A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520. A specially craft... | 7.8 - HIGH | 2023-09-27 | 2023-09-28 |
| CVE-2022-33896 json | A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office fi... | 7.8 - HIGH | 2022-10-07 | 2022-10-11 |
| CVE-2021-21958 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.8 - HIGH | 2022-02-16 | 2022-05-12 |
| CVE-2020-7882 json | Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete... | 9.1 - CRITICAL | 2021-11-22 | 2021-11-26 |
| CVE-2019-16338 json | The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file. | 7.8 - HIGH | 2020-03-19 | 2020-03-27 |
| CVE-2019-16337 json | The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file. | 7.8 - HIGH | 2020-03-19 | 2020-03-27 |
| CVE-2018-5201 json | Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earl... | 5.5 - MEDIUM | 2018-12-21 | 2020-08-24 |
| CVE-2018-5195 json | Hancom NEO versions 9.6.1.5183 and earlier have a buffer Overflow vulnerability that leads remote attackers to execute arbitr... | 9.8 - CRITICAL | 2018-01-17 | 2018-02-02 |
| CVE-2017-2819 json | An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) of Hancom Thinkf... | 7.8 - HIGH | 2017-05-24 | 2022-04-19 |
| CVE-2016-4298 json | When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt t... | 7.8 - HIGH | 2017-01-06 | 2017-01-11 |
| CVE-2016-4296 json | When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 wi... | 7.8 - HIGH | 2017-01-06 | 2017-01-11 |
| CVE-2016-4295 json | When opening a Hangul Hcell Document (.cell) and processing a particular record within the Workbook stream, an index miscalcu... | 7.8 - HIGH | 2017-01-06 | 2017-01-11 |
| CVE-2016-4294 json | When opening a Hangul Hcell Document (.cell) and processing a property record within the Workbook stream, Hancom Office 2014 ... | 7.8 - HIGH | 2017-01-06 | 2017-01-11 |
| CVE-2016-4293 json | Multiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle functions in ... | 7.8 - HIGH | 2017-04-20 | 2017-04-27 |
| CVE-2016-4292 json | When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a sta... | 7.8 - HIGH | 2017-01-06 | 2017-01-11 |
| CVE-2016-4291 json | When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a fie... | 7.8 - HIGH | 2017-01-06 | 2017-01-11 |
| CVE-2016-4290 json | When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt t... | 7.8 - HIGH | 2017-01-06 | 2017-01-11 |
| CVE-2015-6585 json | hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by levera... | 7.8 - HIGH | 2017-07-25 | 2017-08-10 |
| CVE-2015-2810 json | Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.... | 7.5 - HIGH | 2015-05-15 | 2016-12-03 |
| CVE-2013-7420 json | Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute... | 7.5 - HIGH | 2015-01-12 | 2019-04-12 |
Known software with vulnerabilities from Hancom
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Hancom | Hancom Office 2010 | 8.5.6.1107 |
| Application | Hancom | Hancom Office 2010 Se | 8.5.5 |
| Application | Hancom | Hancom Office 2014 | 9.1.0.2176 |
| Application | Hancom | Hancom Office 2018 | 10.0.0.8214 |
| Application | Hancom | Hancom Office Neo | 9.6.1.10472 |
| Application | Hancom | Hangul Word Processor | 2014 |