Back

CVE-2005-2972

Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow user-assisted attackers to execute arbitrary code via an RTF file with long identifiers, which are not properly handled in the (1) ParseLevelText, (2) getCharsInsideBrace, (3) HandleLists, (4) or (5) HandleAbiLists functions in ie_imp_RTF.cpp, a different vulnerability than CVE-2005-2964.

Published: Oct 23, 2005 Modified: Jun 16, 2026
CWE-119

CVSS Metrics

Affected Products (1)

Vendor Product Version
abisource community_abiword *

GitHub Security Advisory GHSA-hw2f-4q5v-cv5j

Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow...

Risk Scores

CVSS Score 5.1 / 10
EPSS Score 4.10%

Top 10% most likely to be exploited

Threat Score 21.6 / 100

Data Sources

NVD EPSS GitHub