Antiword Project maintains a lightweight document-conversion utility designed to extract text and metadata from Microsoft Word files, occupying a narrow but specialized niche in document-processing tooling. The observed vulnerability profile centers on memory-buffer handling in the parsing and conversion logic, reflecting the complexity of reverse-engineered binary file formats. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Antiword Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8123MEDIUM Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document. | Dec 5, 2014 | 5.0 | 20 | NO | NO |
The (1) kantiword (kantiword.sh) and (2) gantiword (gantiword.sh) scripts in antiword 0.35 and earlier allow local users to overwrite arbitrary files via a symlink attack on tempor | Dec 31, 2005 | 1.9 | 11 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Antiword Project.
Media articles that mention a CVE ID that affects a product developed by Antiword Project — matched by CVE ID, not by vendor name.