Hancom develops a suite of office productivity applications and word processors that are prominently deployed in East Asian markets, with a vulnerability footprint spanning multiple product generations including Hancom Office and Hangul Word Processor. The vendor's disclosures cluster around memory-safety and bounds-checking weaknesses—improper buffer restrictions, out-of-bounds writes, use-after-free conditions, integer overflows, and stack-based buffer overflows—that reflect the native-code implementation and parsing demands of document processing software. Vulnerabilities affecting this vendor lean toward serious outcomes, with a meaningful share reaching critical severity. Defenders should prioritize patches for this vendor's products, particularly in environments where older office suite versions remain in active use, since document-processing flaws can be weaponized through seemingly benign user interaction. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hancom over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7420HIGH Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute in a TEXTART XML element in an HML file. | Jan 12, 2015 | 7.5 | 38 | NO | YES |
CVE-2018-5195CRITICAL Hancom NEO versions 9.6.1.5183 and earlier have a buffer Overflow vulnerability that leads remote attackers to execute arbitrary commands when performing the hyperlink Attributes i | Jan 17, 2018 | 9.8 | 32 | NO | NO |
CVE-2020-7882CRITICAL Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains pa | Nov 22, 2021 | 9.1 | 28 | NO | NO |
CVE-2012-1206HIGH Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (1) JPG image to the ImportGR in the JPG | Feb 24, 2012 | 9.3 | 28 | NO | NO |
CVE-2021-21958HIGH A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353. A specially-crafted malformed file can lead to memory c | Feb 16, 2022 | 7.8 | 26 | NO | NO |
CVE-2016-4293HIGH Multiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle functions in Hancom Office 2014 VP allow remote attackers to execute | Apr 20, 2017 | 7.8 | 26 | NO | NO |
CVE-2023-51598HIGH Hancom Office Word DOC File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio | May 3, 2024 | 8.8 | 25 | NO | NO |
CVE-2016-4294HIGH When opening a Hangul Hcell Document (.cell) and processing a property record within the Workbook stream, Hancom Office 2014 will attempt to allocate space for an element using a l | Jan 6, 2017 | 7.8 | 25 | NO | NO |
CVE-2022-33896HIGH A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memor | Oct 7, 2022 | 7.8 | 24 | NO | NO |
CVE-2016-4296HIGH When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end | Jan 6, 2017 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hancom.
Media articles that mention a CVE ID that affects a product developed by Hancom — matched by CVE ID, not by vendor name.