V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2012-0037
DEB
Medium

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and o…

CVSS
6.5
Medium
EPSS
0.14
p95
Published
2012-01-01
Updated
2012-01-01
Description

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

Tags · CWE
Pre-auth
CWE-611
CAPEC-221
Affected products
Debian_linux
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Timeline
2012-01-01
Published
2012-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.137 · p95
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
openoffice.orgTracked
openoffice.orgTracked
raptorTracked
raptorTracked
raptorTracked
debian_linux*Tracked
enterprise_linux_desktop*Tracked
enterprise_linux_eus*Tracked
enterprise_linux_server*Tracked
enterprise_linux_server_aus*Tracked
enterprise_linux_workstation*Tracked
fedora*Tracked
gluster_storage_server_for_on-premise*Tracked
libreoffice*Tracked
openoffice*Tracked
raptor*Tracked
storage*Tracked
storage_for_public_cloud*Tracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities