Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hancom

First CVE: Feb 24, 2012Active for: 14 yearsTotal CVEs: 25
50.0
VTI Score
TOP TARGET

Hancom develops a suite of office productivity applications and word processors that are prominently deployed in East Asian markets, with a vulnerability footprint spanning multiple product generations including Hancom Office and Hangul Word Processor. The vendor's disclosures cluster around memory-safety and bounds-checking weaknesses—improper buffer restrictions, out-of-bounds writes, use-after-free conditions, integer overflows, and stack-based buffer overflows—that reflect the native-code implementation and parsing demands of document processing software. Vulnerabilities affecting this vendor lean toward serious outcomes, with a meaningful share reaching critical severity. Defenders should prioritize patches for this vendor's products, particularly in environments where older office suite versions remain in active use, since document-processing flaws can be weaponized through seemingly benign user interaction. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hancom over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2012
14 years ago
Most Recent CVE
May 3, 2024
812 days ago

Products(17 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-7420HIGH
Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute in a TEXTART XML element in an HML file.
Jan 12, 20157.538NOYES
CVE-2018-5195CRITICAL
Hancom NEO versions 9.6.1.5183 and earlier have a buffer Overflow vulnerability that leads remote attackers to execute arbitrary commands when performing the hyperlink Attributes i
Jan 17, 20189.832NONO
CVE-2020-7882CRITICAL
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains pa
Nov 22, 20219.128NONO
CVE-2012-1206HIGH
Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (1) JPG image to the ImportGR in the JPG
Feb 24, 20129.328NONO
CVE-2021-21958HIGH
A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353. A specially-crafted malformed file can lead to memory c
Feb 16, 20227.826NONO
CVE-2016-4293HIGH
Multiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle functions in Hancom Office 2014 VP allow remote attackers to execute
Apr 20, 20177.826NONO
CVE-2023-51598HIGH
Hancom Office Word DOC File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio
May 3, 20248.825NONO
CVE-2016-4294HIGH
When opening a Hangul Hcell Document (.cell) and processing a property record within the Workbook stream, Hancom Office 2014 will attempt to allocate space for an element using a l
Jan 6, 20177.825NONO
CVE-2022-33896HIGH
A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memor
Oct 7, 20227.824NONO
CVE-2016-4296HIGH
When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end
Jan 6, 20177.824NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
88%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local18 (72.0%)
Network4 (16.0%)
Unknown3 (12.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (88.0%)
High0 (0.0%)
Unknown3 (12.0%)
User Interaction
None2 (8.0%)
Unknown3 (12.0%)
Required20 (80.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None22 (88.0%)
Unknown3 (12.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hancom.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hancom — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hancom's Products

View all 5 CNAs →

Top CWEs