← Vulnerability feed

Vulnerability record · CVE-2020-28587 · published 23 February 2021

CVE-2020-28587: Softmaker planmaker 2021 heap-based buffer overflow vulnerability

Softmaker · Planmaker 2021

A specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object that is smaller than the size used for the copy, which will cause a heap-based buffer overflow. An attacker can entice the victim to open a document to trigger this vulnerability. This affects SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014).

7.8 CVSS 3.1 High EPSS 0.95% · top 40.3% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score, v2 6.8
0.95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object that is smaller than the size used for the copy, which will cause a heap-based buffer overflow. An attacker can entice the victim to open a document to trigger this vulnerability. This affects SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014).

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-28587 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-13581Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityIn SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014), a specially crafted document can cause the document parser to copy data f…EPSS 1.0%7.8CVE-2020-27250Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityIn SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014), a specially crafted document can cause the document parser to copy data f…EPSS 0.95%7.8CVE-2020-13586Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityA memory corruption vulnerability exists in the Excel Document SST Record 0x00fc functionality of SoftMaker Software GmbH SoftMaker Office PlanMaker …EPSS 1.5%7.8CVE-2020-27247Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityA specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…EPSS 1.2%7.8CVE-2020-27248Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityA specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…EPSS 1.2%7.8CVE-2020-27249Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityA specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…EPSS 1.2%7.8CVE-2020-13579SoftMaker PlanMaker document parsing integer overflow leads to heap overflowSoftMaker Office 2021's PlanMaker application has an integer overflow in its document parsing code. A crafted document causes arithmetic to overflow,…EPSS 71%analysed7.8CVE-2020-13580SoftMaker PlanMaker heap buffer overflow via crafted documentSoftMaker Office 2021's PlanMaker application has a heap-based buffer overflow in its document parsing functionality. The parser trusts a length valu…EPSS 71%analysed

Source: NIST National Vulnerability Database (record CVE-2020-28587), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.