« Back to list

CVE-2012-3456

Status: ModifiedHigh (7.5)—💥 Exploit

Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

💥 Public exploits

Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2012-3456",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-08-20T18:55:03.810",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00026.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=136733075705494&w=2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://media.blackhat.com/bh-us-12/Briefings/C_Miller/BH_US_12_Miller_NFC_attack_surface_WP.pdf",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/50050",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.kde.org/info/security/advisory-20120810-1.txt",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/04/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/04/5",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/06/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/06/6",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/10/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/54816",
      "tags": [
        "Exploit"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1525-1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77482",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00026.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=136733075705494&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://media.blackhat.com/bh-us-12/Briefings/C_Miller/BH_US_12_Miller_NFC_attack_surface_WP.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/50050",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kde.org/info/security/advisory-20120810-1.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/04/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/04/5",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/06/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/06/6",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/10/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/54816",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1525-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77482",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document.  NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase."
    },
    {
      "lang": "es",
      "value": "Un desbordamiento de búfer basado en memoria dinámica ('heap') en la función de lectura 'read' en filters/words/msword-odf/wv2/src/styles.cpp en el filtro de importación en Microsoft Calligra v2.4.3 y anteriores permite a atacantes remotos provocar una denegación de servicio (por caída de la aplicación) y posiblemente ejecutar código de su elección a través de un estilo de ODF diseñado para tal fin en un documento ODF. NOTA: esta es la misma vulnerabilidad que CVE-2012-3455, pero fue dividido por la CNA aunque Calligra y KOffice comparten el mismo código base.\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:43:15.483",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:calligra:calligra:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3909F4A0-3FC4-4640-BCCF-201D66D3BF98",
              "versionEndIncluding": "2.4.3"
            },
            {
              "criteria": "cpe:2.3:a:calligra:calligra:2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6AA6D16D-E003-4E9B-8E1F-E2805EFF4297"
            },
            {
              "criteria": "cpe:2.3:a:calligra:calligra:2.4:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "449711D4-5FC0-4701-81ED-A527E5416BEC"
            },
            {
              "criteria": "cpe:2.3:a:calligra:calligra:2.4:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6AAC65A7-ED2B-48EC-9A19-6D3058E4252C"
            },
            {
              "criteria": "cpe:2.3:a:calligra:calligra:2.4:beta4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CF3793D-3698-4003-B1EA-28DC038E0C1D"
            },
            {
              "criteria": "cpe:2.3:a:calligra:calligra:2.4:beta6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B02ADDD0-60EE-4123-AF85-C17C878E3AA2"
            },
            {
              "criteria": "cpe:2.3:a:calligra:calligra:2.4:beta7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F891F8A7-282A-4D6F-A490-FA24F8EAF5D6"
            },
            {
              "criteria": "cpe:2.3:a:calligra:calligra:2.4:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B538295-C391-45E1-84F9-19DFC6798894"
            },
            {
              "criteria": "cpe:2.3:a:calligra:calligra:2.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53B7517B-69DC-4A69-BC1E-B4F6FAC6C5BE"
            },
            {
              "criteria": "cpe:2.3:a:calligra:calligra:2.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6ECE04D2-C0A0-47B0-BE2A-15F7E9789500"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}