CVE-2013-3159
published 2013-09-11CVE-2013-3159: Microsoft Excel 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Excel Viewer; and Microsoft Office Compatibility Pack SP3 allow remote attackers to read arbitrary…
PriorityP336medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
17.38%
96.8th percentile
Microsoft Excel 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Excel Viewer; and Microsoft Office Compatibility Pack SP3 allow remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka "XML External Entities Resolution Vulnerability."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4vq7-844p-76r2: Microsoft Excel 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Excel Viewer; and Microsoft Office Compatibility Pack SP3 allow remote attackers to read arb
ghsa_unreviewed·2022-05-14
CVE-2013-3159 [MEDIUM] CWE-20 GHSA-4vq7-844p-76r2: Microsoft Excel 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Excel Viewer; and Microsoft Office Compatibility Pack SP3 allow remote attackers to read arb
Microsoft Excel 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Excel Viewer; and Microsoft Office Compatibility Pack SP3 allow remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka "XML External Entities Resolution Vulnerability."
Red Hat
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
vendor_redhat·2016-03-24·CVSS 4.3
CVE-2016-3159 [MEDIUM] xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
Statement: This issue does not affect the Xen hypervisor packages as shipped with Red Hat Enterprise Linux 5.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.us-cert.gov/ncas/alerts/TA13-253Ahttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-073https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18686http://www.us-cert.gov/ncas/alerts/TA13-253Ahttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-073https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18686
2013-09-11
Published