Description
Multiple integer overflows in the WV library in wvWare (formerly mswordview) before 1.2.3, as used by AbiWord, KWord, and possibly other products, allow user-assisted remote attackers to execute arbitrary code via a crafted Microsoft Word (DOC) file that produces (1) large LFO clfolvl values in the wvGetLFO_records function or (2) a large LFO nolfo value in the wvGetFLO_PLF function.
Published: 2006-10-28
Score: 5.1 Medium
EPSS: 8.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2006-4501 Multiple integer overflows in the WV library in wvWare (formerly mswordview) before 1.2.3, as used by AbiWord, KWord, and possibly other products, allow user-assisted remote attackers to execute arbitrary code via a crafted Microsoft Word (DOC) file that produces (1) large LFO clfolvl values in the wvGetLFO_records function or (2) a large LFO nolfo value in the wvGetFLO_PLF function.
Ubuntu USN Ubuntu USN USN-374-1 wvWare vulnerability
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T19:14:47.481Z

Reserved: 2006-08-31T00:00:00.000Z

Link: CVE-2006-4513

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2006-10-28T00:07:00.000

Modified: 2026-04-23T00:35:47.467

Link: CVE-2006-4513

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses