Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-12608

26
FAUCET Score

CVE-2017-12608 is a high-severity vulnerability affecting Apache OpenOffice Writer before version 4.1.4, specifically within its DOC file parser. Attackers can exploit this by crafting malicious documents, leading to memory corruption and application crashes, with a potential for arbitrary code execution. The vulnerability has a CVSS score of 7.8, indicating a high impact on confidentiality, integrity, and availability, requiring user interaction to trigger. While no public exploit code or active exploitation has been observed, there is some community discussion and media coverage surrounding this flaw.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.1.4CPE matchmatch criteria
cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.89%
Probability of exploitation in next 30 days
EPSS Percentile
85.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0289 is in the 86th percentile among its peer group of 11,621 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

asteriskpatch availablevia llm_extracted
Fixed in: 5.0.2/5.1.0
View patch
check_pointpatch availablevia llm_extracted
Fixed in: 5.0.2/5.1.0
View patch
denopatch availablevia llm_extracted
Fixed in: 4.1.4
View patch
libreofficepatch availablevia llm_extracted
Fixed in: 4.1.4
View patch
nessuspatch availablevia llm_extracted
Fixed in: 4.1.4
postgresqlpatch availablevia llm_extracted
Fixed in: 4.1.4
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: libreoffice

Vendor Advisories (7)

redhatCVE-2017-12608Moderate

libreoffice: Out-of-bounds write in the WW8RStyle::ImportOldFormatStyles functionality

Oct 26, 2017
asteriskllm-asterisk-78a9350750b3c988

Out-of-Bounds Write in Writer's ImportOldFormatStyles

check_pointllm-check_point-7548e7a650875102

Out-of-Bounds Write in Writer's ImportOldFormatStyles

denollm-deno-71b483caedf60f31

Out-of-Bounds Write in Writer's ImportOldFormatStyles

postgresqlllm-postgresql-97e94e91a2ff5f1b

Out-of-Bounds Write in Writer's ImportOldFormatStyles

libreofficellm-libreoffice-89b07211858ca770

Out-of-Bounds Write in Writer's ImportOldFormatStyles

nessusllm-nessus-73bffab962ac8b7b

Out-of-Bounds Write in Writer's ImportOldFormatStyles

References

lists.debian.org / debian-lts-announce/2017/12/msg00017.html
Third Party Advisory
debian.org / security/2017/dsa-4022
Third Party Advisory
openoffice.org / security/cves/CVE-2017-12608.html
Release NotesVendor Advisory
securityfocus.com / bid/101585
Third Party AdvisoryVDB Entry
securitytracker.com / id/1039733
Third Party AdvisoryVDB Entry
securitytracker.com / id/1039735
Third Party AdvisoryVDB Entry