suse · CVE-2016-5851

Quick triage

Priority: medium Published: 2021-05-30 13:44:17 UTC Updated: 2023-12-09 01:14:55 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document.

Description:

python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document.

cvelogic Threat Intelligence