CVE Vulnerabilities

CVE-2016-4216

Published: Jul 13, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

XMPCore in Adobe XMP Toolkit for Java before 5.1.3 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected Software

NameVendorStart VersionEnd Version
Xmp_toolkitAdobe*5.1.2 (including)
Libxmpcore-javaUbuntuartful*
Libxmpcore-javaUbuntubionic*
Libxmpcore-javaUbuntucosmic*
Libxmpcore-javaUbuntudevel*
Libxmpcore-javaUbuntudisco*
Libxmpcore-javaUbuntueoan*
Libxmpcore-javaUbuntuesm-apps/bionic*
Libxmpcore-javaUbuntuesm-apps/focal*
Libxmpcore-javaUbuntuesm-apps/jammy*
Libxmpcore-javaUbuntuesm-apps/noble*
Libxmpcore-javaUbuntuesm-apps/xenial*
Libxmpcore-javaUbuntufocal*
Libxmpcore-javaUbuntugroovy*
Libxmpcore-javaUbuntuhirsute*
Libxmpcore-javaUbuntuimpish*
Libxmpcore-javaUbuntujammy*
Libxmpcore-javaUbuntukinetic*
Libxmpcore-javaUbuntulunar*
Libxmpcore-javaUbuntumantic*
Libxmpcore-javaUbuntunoble*
Libxmpcore-javaUbuntuoracular*
Libxmpcore-javaUbuntuplucky*
Libxmpcore-javaUbuntuquesting*
Libxmpcore-javaUbuntutrusty*
Libxmpcore-javaUbuntuupstream*
Libxmpcore-javaUbuntuwily*
Libxmpcore-javaUbuntuxenial*
Libxmpcore-javaUbuntuyakkety*
Libxmpcore-javaUbuntuzesty*

References