Libwpd is a specialized parsing library that handles WordPerfect document formats and is embedded across document-processing and office-productivity tools, creating a narrow but strategically positioned supply-chain footprint. The observed vulnerability signal centers on memory-safety issues, specifically improper buffer-boundary checks and out-of-bounds reads, which are characteristic of a format parser handling untrusted input. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libwpd over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2149HIGH The WPXContentListener::_closeTableRow function in WPXContentListener.cpp in libwpd 0.8.8, as used by OpenOffice.org (OOo) before 3.4, allows remote attackers to execute arbitrary | Jun 21, 2012 | 7.5 | 31 | NO | NO |
CVE-2007-0002HIGH Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application | Mar 16, 2007 | 9.3 | 28 | NO | NO |
CVE-2017-14226HIGH WP1StylesListener.cpp, WP5StylesListener.cpp, and WP42StylesListener.cpp in libwpd 0.10.1 mishandle iterators, which allows remote attackers to cause a denial of service (heap-base | Sep 9, 2017 | 7.5 | 25 | NO | NO |
CVE-2018-19208MEDIUM In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This i | Nov 12, 2018 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libwpd.
Media articles that mention a CVE ID that affects a product developed by Libwpd — matched by CVE ID, not by vendor name.