Hmtalk maintains a narrowly scoped portfolio centered on document and office productivity applications such as Daview Indy, Daoffice, and the Dava product line. The recurring vulnerability signal across these products reflects memory-safety and input-handling weaknesses, including out-of-bounds writes and reads, heap-based buffer overflows, integer overflow conditions, and improper input validation that are characteristic of native applications processing complex document formats. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hmtalk over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7872HIGH DaviewIndy v8.98.7.0 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed format file that is mishandled by DaviewIndy. Attackers c | Jul 12, 2021 | 7.8 | 25 | NO | NO |
CVE-2020-7818HIGH DaviewIndy 8.98.9 and earlier has a Heap-based overflow vulnerability, triggered when the user opens a malformed PDF file that is mishandled by Daview.exe. Attackers could exploit | Jul 17, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-7816HIGH A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker to cause an arbitrary code execution on a | Jun 30, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-7852HIGH DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed ex.j2c format file that is mishandled by Daview.exe. Attackers could exploit this and | Mar 24, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-7827HIGH DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers coul | Jul 30, 2020 | 7.8 | 24 | NO | NO |
CVE-2020-7823HIGH DaviewIndy has a Memory corruption vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary | Aug 4, 2020 | 7.8 | 20 | NO | NO |
CVE-2020-7822HIGH DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrar | Aug 4, 2020 | 7.8 | 20 | NO | NO |
CVE-2020-7829HIGH DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers | Jul 30, 2020 | 7.8 | 20 | NO | NO |
CVE-2020-7828HIGH DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers | Jul 30, 2020 | 7.8 | 20 | NO | NO |
CVE-2019-9137HIGH DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed Image file that is mishandled by Daview.exe. Attackers could | Apr 25, 2019 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hmtalk.
Media articles that mention a CVE ID that affects a product developed by Hmtalk — matched by CVE ID, not by vendor name.