CVE Feed

    Dashboard / CVE / CVE-2022-39843

    CVE-2022-39843

    123elf Lotus 1-2-3 before 1.0.0rc3 for Linux, and Lotus 1-2-3 R3 for UNIX and other platforms through 9.8.2, allow attackers to execute arbitrary code via a crafted worksheet. This occurs because of a stack-based buffer overflow in the cell format processing routines, as demonstrated by a certain function call from process_fmt() that can be reached via a w3r_format element in a wk3 document.

    Published:Sep 5, 2022
    Last Modified:Nov 21, 2024
    EPS:Sep 5, 2022
    EPSS Score:0.00126
    CVSS Score:7.8

    Affected Products

    Vendor
    Linux
    Product
    Linux Kernel
    Vendor
    Lotus 1-2-3 Project
    Product
    Lotus 1-2-3

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High