← Vulnerability feed

Vulnerability record · CVE-2006-6120 · published 3 December 2006

CVE-2006-6120: Kde koffice vulnerability

Kde · Koffice

Integer overflow in the KPresenter import filter for Microsoft PowerPoint files (filters/olefilters/lib/klaola.cc) in KOffice before 1.6.1 allows user-assisted remote attackers to execute arbitrary code via a crafted PPT file, which results in a heap-based buffer overflow.

6.8 CVSS 2.0 Medium EPSS 4.2% · top 9.3%
6.8CVSS 2.0 base score
4.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
36References
16 Jun 2026Last modified by NVD

Description

Integer overflow in the KPresenter import filter for Microsoft PowerPoint files (filters/olefilters/lib/klaola.cc) in KOffice before 1.6.1 allows user-assisted remote attackers to execute arbitrary code via a crafted PPT file, which results in a heap-based buffer overflow.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/23143 Vendor Advisory
http://secunia.com/advisories/23162 Vendor Advisory
http://secunia.com/advisories/23220
http://secunia.com/advisories/23409
http://secunia.com/advisories/24218
http://security.gentoo.org/glsa/glsa-200612-05.xml
http://securitytracker.com/id?1017318
http://websvn.kde.org/branches/koffice/1.6/koffice/filters/olefilters/lib/klaola.cc?rev=607037&r1=566347&r2=607037 PatchVendor Advisory
http://www.kde.org/info/security/advisory-20061204-1.txt
http://www.koffice.org/announcements/changelog-1.6.1.php PatchVendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2006:222
http://www.novell.com/linux/security/advisories/2006_29_sr.html
http://www.redhat.com/support/errata/RHSA-2007-0010.html
http://www.securityfocus.com/archive/1/453550/100/0/threaded
http://www.securityfocus.com/bid/21354 PatchVendor Advisory
http://www.ubuntu.com/usn/usn-388-1 PatchVendor Advisory
http://www.vupen.com/english/advisories/2006/4771
https://exchange.xforce.ibmcloud.com/vulnerabilities/30624
http://secunia.com/advisories/23143 Vendor Advisory
http://secunia.com/advisories/23162 Vendor Advisory
http://secunia.com/advisories/23220
http://secunia.com/advisories/23409
http://secunia.com/advisories/24218
http://security.gentoo.org/glsa/glsa-200612-05.xml
http://securitytracker.com/id?1017318
http://websvn.kde.org/branches/koffice/1.6/koffice/filters/olefilters/lib/klaola.cc?rev=607037&r1=566347&r2=607037 PatchVendor Advisory
http://www.kde.org/info/security/advisory-20061204-1.txt
http://www.koffice.org/announcements/changelog-1.6.1.php PatchVendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2006:222
http://www.novell.com/linux/security/advisories/2006_29_sr.html
http://www.redhat.com/support/errata/RHSA-2007-0010.html
http://www.securityfocus.com/archive/1/453550/100/0/threaded
http://www.securityfocus.com/bid/21354 PatchVendor Advisory
http://www.ubuntu.com/usn/usn-388-1 PatchVendor Advisory
http://www.vupen.com/english/advisories/2006/4771
https://exchange.xforce.ibmcloud.com/vulnerabilities/30624

Track CVE-2006-6120 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-0888Easy software products cups vulnerabilityMultiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to …EPSS 9.5%10.0CVE-2004-0889Easy software products cups vulnerabilityMultiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (cras…EPSS 6.2%7.5CVE-2012-3455Kde koffice memory buffer overflow vulnerabilityHeap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and ea…EPSS 5.3%7.5CVE-2005-2971Kde koffice vulnerabilityHeap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a crafted …EPSS 6.4%7.5CVE-2005-0206Ascii ptex vulnerabilityThe patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributi…EPSS 3.0%5.0CVE-2005-3624Easy software products cups vulnerabilityThe CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attac…EPSS 2.3%5.0CVE-2005-3626Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2006-6120), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.