Antiword is a document-conversion utility designed to extract text from Microsoft Word files, with its vulnerability exposure centered on a single, narrowly scoped product. The durable signal reflects the file-parsing attack surface inherent to the tool: its disclosures center on improper link resolution, a weakness class that arises when the parser follows embedded references without validating their target paths. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Antiword over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8123MEDIUM Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document. | Dec 5, 2014 | 5.0 | 20 | NO | NO |
The (1) kantiword (kantiword.sh) and (2) gantiword (gantiword.sh) scripts in antiword 0.35 and earlier allow local users to overwrite arbitrary files via a symlink attack on tempor | Dec 31, 2005 | 1.9 | 11 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Antiword.
Media articles that mention a CVE ID that affects a product developed by Antiword — matched by CVE ID, not by vendor name.