The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.
CVSS Metrics