CVE-2012-3455: Kde Koffice

High severity, CVSS 7.5. EPSS: 5.3% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.

Affected products

  • Kde Koffice: up to and including 2.3.3; version 1.2 only; version 1.2.1 only; version 1.3 only; version 1.3.1 only; version 1.3.2 only; …

Published 2012-08-20. Last modified 2026-06-16.