CVE-2012-1206: Hancom Office 2010 SE
High severity, CVSS 9.3. EPSS: 4.8% chance of exploitation in the next 30 days.
Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (1) JPG image to the ImportGR in the JPG image filter module (HncJpeg10.flt) or (2) PNG image to the PNG image filter module (HncPng10.flt), which triggers a heap-based buffer overflow.
Affected products
- Hancom Hancom Office 2010 SE: version 8.5.5 only
Published 2012-02-24. Last modified 2026-06-16.