CVE-2020-13545
An exploitable signed conversion vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon usage of this buffer the application will write outside its bounds resulting in a heap-based memory corruption. An attacker can entice the victim to open a document to trigger this vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.40%
- CWE
- CWE-196
- Published
- 2021-01-06
- Last modified
- 2026-03-14
Affected products
- n/a Softmaker
Weakness type
Related vulnerabilities
- CVE-2026-58317 — Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term...
- CVE-2026-14454 — Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed
- CVE-2026-34155 — RAUC: Improper Signing of Plain Bundles Exceeding 2 GiB
- CVE-2023-0185 — NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where sign...
- CVE-2022-36025 — Incorrect Conversion between Numeric Types in Besu Ethereum Client
- CVE-2020-7067 — OOB Read in urldecode()