← All CVEs

CVE-2012-0037

medium · 6.5

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

6.5
CVSS
13.7%
EPSS (exploit prob.)
96th
EPSS percentile
2012-06-17
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Weaknesses

CWE-611

Affected products

VendorProductAffected versions
librdfraptor< 2.0.7
libreofficelibreoffice< 3.4.6
libreofficelibreoffice3.5.0
apacheopenoffice3.3.0
apacheopenoffice3.4.0
fedoraprojectfedora16
fedoraprojectfedora17
redhatgluster_storage_server_for_on-premise2.0
redhatstorage2.0
redhatstorage_for_public_cloud2.0
redhatenterprise_linux_desktop5.0
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_eus6.2
redhatenterprise_linux_server5.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server_aus6.2
redhatenterprise_linux_workstation5.0
redhatenterprise_linux_workstation6.0
debiandebian_linux6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-0037