Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-0037

29
FAUCET Score

CVE-2012-0037 describes a user-assisted XML External Entity (XXE) vulnerability in Redland Raptor (libraptor) versions prior to 2.0.7, impacting products like OpenOffice and LibreOffice. This flaw allows remote attackers to read arbitrary files by tricking a user into opening a specially crafted RDF document containing XXE declarations. Rated with a CVSS score of 6.5 (Medium), the vulnerability requires user interaction (UI:R) but can lead to high confidentiality impact (C:H) without affecting integrity or availability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.0.7CPE matchmatch criteria
cpe:2.3:a:librdf:raptor:*:*:*:*:*:*:*:*
< 3.4.6CPE matchmatch criteria
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
3.5.0CPE matchmatch criteria
cpe:2.3:a:libreoffice:libreoffice:3.5.0:*:*:*:*:*:*:*
3.3.0CPE matchmatch criteria
cpe:2.3:a:apache:openoffice:3.3.0:*:*:*:*:*:*:*
3.4.0CPE matchmatch criteria
cpe:2.3:a:apache:openoffice:3.4.0:beta:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
13.68%
Probability of exploitation in next 30 days
EPSS Percentile
96.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.1368 is in the 98th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

asteriskpatch availablevia llm_extracted
Fixed in: 3.4.6/3.5.1
View patch
check_pointpatch availablevia llm_extracted
Fixed in: 3.4.6/3.5.1
View patch
denopatch availablevia llm_extracted
Fixed in: 3.3
View patch
github_advisorypatch availablevia nvd_reference
View patch
libreofficepatch availablevia llm_extracted
Fixed in: 3.3
View patch
nessuspatch availablevia llm_extracted
Fixed in: 3.3
postgresqlpatch availablevia llm_extracted
Fixed in: 3.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: raptor-0:1.4.18-5.el6_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: openoffice.org-1:3.1.1-19.10.el5_8.1
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: openoffice.org

Vendor Advisories (7)

redhatCVE-2012-0037Important

raptor: XML External Entity (XXE) attack via RDF files

Mar 22, 2012
asteriskllm-asterisk-55526ff207a443c5

XML Entity Expansion flaw by processing RDF file

check_pointllm-check_point-84bf8792e80a4980

XML Entity Expansion flaw by processing RDF file

denollm-deno-247fbfbb3d01208d

OpenOffice.org data leakage vulnerability

postgresqlllm-postgresql-c6f9223075e8d757

OpenOffice.org data leakage vulnerability

libreofficellm-libreoffice-765c2c33dab98e36

OpenOffice.org data leakage vulnerability

nessusllm-nessus-639f150b550d2415

OpenOffice.org data leakage vulnerability

References

blog.documentfoundation.org / 2012/03/22/tdf-announces-libreoffice-3-4-6
Release Notes
librdf.org / raptor/RELEASE.html
Release Notes
lists.fedoraproject.org / pipermail/package-announce/2012-April/077708.html
Mailing List
lists.fedoraproject.org / pipermail/package-announce/2012-April/078242.html
Mailing List
rhn.redhat.com / errata/RHSA-2012-0410.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2012-0411.html
Third Party Advisory
secunia.com / advisories/48479
Broken LinkVendor Advisory
secunia.com / advisories/48493
Broken LinkVendor Advisory
secunia.com / advisories/48494
Broken Link
secunia.com / advisories/48526
Broken LinkVendor Advisory
secunia.com / advisories/48529
Broken LinkVendor Advisory
secunia.com / advisories/48542
Broken LinkVendor Advisory
secunia.com / advisories/48649
Broken Link
secunia.com / advisories/50692
Broken Link
secunia.com / advisories/60799
Broken Link
security.gentoo.org / glsa/glsa-201209-05.xml
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/74235
Third Party AdvisoryVDB Entry
github.com / dajobe/raptor/commit/a676f235309a59d4aa78eeffd2574ae5d341fcb0
Patch
lists.apache.org / thread.html/re0504f08000df786e51795940501e81a5d0ae981ecca68141e87ece0%40%3Ccommits.openoffice.apache.org%3E
Mailing ListPatch
vsecurity.com / resources/advisory/20120324-1
Broken Link
debian.org / security/2012/dsa-2438
Third Party Advisory
gentoo.org / security/en/glsa/glsa-201408-19.xml
Third Party Advisory
libreoffice.org / advisories/CVE-2012-0037
Vendor Advisory
mandriva.com / security/advisories
Broken Link
mandriva.com / security/advisories
Broken Link
mandriva.com / security/advisories
Broken Link
openoffice.org / security/cves/CVE-2012-0037.html
MitigationPatch
openwall.com / lists/oss-security/2012/03/27/4
ExploitMailing List
osvdb.org / 80307
Broken Link
securityfocus.com / bid/52681
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry