Wvware provides document-conversion libraries and utilities, notably libwmf and wv2, that handle legacy Microsoft Office formats and enable cross-platform document processing. Its vulnerability profile centers on memory-safety issues inherent to parsing complex binary document structures, particularly improper buffer-boundary enforcement in format-handling code. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wvware over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0645HIGH Buffer overflow in the wvHandleDateTimePicture function in wv library (wvWare) 0.7.4 through 0.7.6 and 1.0.0 allows remote attackers to execute arbitrary code via a document with a | Aug 6, 2004 | 10.0 | 28 | NO | NO |
CVE-2015-0848MEDIUM Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image. | Jul 1, 2015 | 6.8 | 27 | NO | NO |
CVE-2006-3376HIGH Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote at | Jul 6, 2006 | 7.5 | 23 | NO | NO |
CVE-2015-4588MEDIUM Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a craft | Jul 1, 2015 | 6.8 | 21 | NO | NO |
CVE-2016-9011MEDIUM The wmf_malloc function in api.c in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (application crash) via a crafted wmf file, which triggers a memory allocati | Mar 23, 2017 | 5.5 | 20 | NO | NO |
CVE-2006-2197MEDIUM Integer overflow in wv2 before 0.2.3 might allow context-dependent attackers to execute arbitrary code via a crafted Microsoft Word document. | Jun 15, 2006 | 6.5 | 18 | NO | NO |
CVE-2015-4695MEDIUM meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file. | Jul 1, 2015 | 5.0 | 17 | NO | NO |
CVE-2006-4513MEDIUM Multiple integer overflows in the WV library in wvWare (formerly mswordview) before 1.2.3, as used by AbiWord, KWord, and possibly other products, allow user-assisted remote attack | Oct 28, 2006 | 5.1 | 16 | NO | NO |
CVE-2015-4696MEDIUM Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command. | Jul 1, 2015 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wvware.
Media articles that mention a CVE ID that affects a product developed by Wvware — matched by CVE ID, not by vendor name.