msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.2%