CVE-2010-4008
Estado: ModificadaMedia (4.3)—
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.70%
- Percentil entre todas las CVEs puntuadas: 85
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (15)
Apache — OpenofficeApple — Iphone OSApple — ItunesApple — MAC OS XApple — SafariCanonical — Ubuntu LinuxDebian — Debian LinuxGoogle — ChromeOpensuse — OpensuseRedhat — Enterprise Linux DesktopRedhat — Enterprise Linux ServerRedhat — Enterprise Linux Server EUSRedhat — Enterprise Linux WorkstationSuse — Suse Linux Enterprise ServerXmlsoft — Libxml2
CWE
- CWE-119
Referencias
- http://blog.bkis.com/en/libxml2-vulnerability-in-google-chrome-and-apple-safari/
- http://code.google.com/p/chromium/issues/detail?id=58731
- http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.html
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html
- http://mail.gnome.org/archives/xml/2010-November/msg00015.html
- http://marc.info/?l=bugtraq&m=130331363227777&w=2
- http://marc.info/?l=bugtraq&m=139447903326211&w=2
- http://rhn.redhat.com/errata/RHSA-2013-0217.html
- http://secunia.com/advisories/40775
- http://secunia.com/advisories/42109
- http://secunia.com/advisories/42175
- http://secunia.com/advisories/42314
- http://secunia.com/advisories/42429
- http://support.apple.com/kb/HT4456
- http://support.apple.com/kb/HT4554
- http://support.apple.com/kb/HT4566
- http://support.apple.com/kb/HT4581
- http://www.debian.org/security/2010/dsa-2128
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:243
- http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.html
- http://www.redhat.com/support/errata/RHSA-2011-1749.html
- http://www.securityfocus.com/bid/44779
- http://www.ubuntu.com/usn/USN-1016-1
- http://www.vupen.com/english/advisories/2010/3046
- http://www.vupen.com/english/advisories/2010/3076
- http://www.vupen.com/english/advisories/2010/3100
- http://www.vupen.com/english/advisories/2011/0230
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12148
- http://blog.bkis.com/en/libxml2-vulnerability-in-google-chrome-and-apple-safari/
- http://code.google.com/p/chromium/issues/detail?id=58731
- http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.html
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html
- http://mail.gnome.org/archives/xml/2010-November/msg00015.html
- http://marc.info/?l=bugtraq&m=130331363227777&w=2
- http://marc.info/?l=bugtraq&m=139447903326211&w=2
- http://rhn.redhat.com/errata/RHSA-2013-0217.html
- http://secunia.com/advisories/40775
- http://secunia.com/advisories/42109
- http://secunia.com/advisories/42175
- http://secunia.com/advisories/42314
- http://secunia.com/advisories/42429
- http://support.apple.com/kb/HT4456
- http://support.apple.com/kb/HT4554
- http://support.apple.com/kb/HT4566
- http://support.apple.com/kb/HT4581
- http://www.debian.org/security/2010/dsa-2128
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:243
- http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.html
- http://www.redhat.com/support/errata/RHSA-2011-1749.html
- http://www.securityfocus.com/bid/44779
- http://www.ubuntu.com/usn/USN-1016-1
- http://www.vupen.com/english/advisories/2010/3046
- http://www.vupen.com/english/advisories/2010/3076
- http://www.vupen.com/english/advisories/2010/3100
- http://www.vupen.com/english/advisories/2011/0230
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12148
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-4008",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "product-security@apple.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-11-17T01:00:02.963",
"references": [
{
"url": "http://blog.bkis.com/en/libxml2-vulnerability-in-google-chrome-and-apple-safari/",
"tags": [
"Broken Link"
],
"source": "product-security@apple.com"
},
{
"url": "http://code.google.com/p/chromium/issues/detail?id=58731",
"tags": [
"Exploit",
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.html",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://mail.gnome.org/archives/xml/2010-November/msg00015.html",
"tags": [
"Mailing List",
"Release Notes",
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://marc.info/?l=bugtraq&m=130331363227777&w=2",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://marc.info/?l=bugtraq&m=139447903326211&w=2",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2013-0217.html",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://secunia.com/advisories/40775",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://secunia.com/advisories/42109",
"tags": [
"Third Party Advisory",
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://secunia.com/advisories/42175",
"tags": [
"Third Party Advisory",
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://secunia.com/advisories/42314",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://secunia.com/advisories/42429",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://support.apple.com/kb/HT4456",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://support.apple.com/kb/HT4554",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://support.apple.com/kb/HT4566",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://support.apple.com/kb/HT4581",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.debian.org/security/2010/dsa-2128",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:243",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.html",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2011-1749.html",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.securityfocus.com/bid/44779",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.ubuntu.com/usn/USN-1016-1",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.vupen.com/english/advisories/2010/3046",
"tags": [
"Permissions Required"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.vupen.com/english/advisories/2010/3076",
"tags": [
"Permissions Required"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.vupen.com/english/advisories/2010/3100",
"tags": [
"Permissions Required"
],
"source": "product-security@apple.com"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0230",
"tags": [
"Permissions Required"
],
"source": "product-security@apple.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12148",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "http://blog.bkis.com/en/libxml2-vulnerability-in-google-chrome-and-apple-safari/",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://code.google.com/p/chromium/issues/detail?id=58731",
"tags": [
"Exploit",
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://mail.gnome.org/archives/xml/2010-November/msg00015.html",
"tags": [
"Mailing List",
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=130331363227777&w=2",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=139447903326211&w=2",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2013-0217.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/40775",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/42109",
"tags": [
"Third Party Advisory",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/42175",
"tags": [
"Third Party Advisory",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/42314",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/42429",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.apple.com/kb/HT4456",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.apple.com/kb/HT4554",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.apple.com/kb/HT4566",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.apple.com/kb/HT4581",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2010/dsa-2128",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:243",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2011-1749.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/44779",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-1016-1",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2010/3046",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2010/3076",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2010/3100",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0230",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12148",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document."
},
{
"lang": "es",
"value": "libxml2 anterior v2.7.8, como el usado en Google Chrome anterior v7.0.517.44, Apple Safari v5.0.2 y anteriores, otros productos, ree desde localizaciones de memoria inválidas durante el procesado de expresiones XPath malformadas, lo que permite a atacantes dependientes del contexto causar una denegación de servicio (caída aplicación) a través de un documento XML. \r\n\r\n"
}
],
"lastModified": "2026-06-16T23:23:58.690",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "21E364C6-AF02-4BA1-8A22-029510C57529",
"versionEndExcluding": "7.0.517.44"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE850901-4B2A-4C98-836A-40683CB02FB4",
"versionEndExcluding": "10.2"
},
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57A2B591-583F-4644-A900-4890FEFEE18C",
"versionEndExcluding": "5.0.4"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D9636697-5FDF-4F67-A95B-D74DDD67A5DD",
"versionEndExcluding": "4.2"
},
{
"criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8D31E3CC-42EA-4519-9077-5C43473CE7C2",
"versionEndExcluding": "10.6.7"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6448A013-E4CD-42C1-80E8-2697D130FBAF",
"versionEndExcluding": "2.7.8"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C757774-08E7-40AA-B532-6F705C8F7639"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "036E8A89-7A16-411F-9D31-676313BB7244"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C18C3CD-969B-4AA3-AE3A-BA4A188F8BFF"
},
{
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C91D2DBF-6DA7-4BA2-9F29-8BD2725A4701"
},
{
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2BCB73E-27BB-4878-AD9C-90C4F20C25A0"
},
{
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D37DF0F-F863-45AC-853A-3E04F9FEC7CA"
},
{
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87614B58-24AB-49FB-9C84-E8DDBA16353B"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE249E1B-A1FD-4E08-AA71-A0E1F10FFE97"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9BBCD86A-E6C7-4444-9D74-F861084090F0"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_server_eus:6.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "413CC30E-5FFE-47A4-B38B-80E3A9B13238"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5ED5807-55B7-47C5-97A6-03233F4FBC3A"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:opensuse:opensuse:11.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FBF7B6A8-3DF9-46EC-A90E-6EF68C39F883"
},
{
"criteria": "cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A01C8B7E-EB19-40EA-B1D2-9AE5EA536C95"
},
{
"criteria": "cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5646FDE9-CF21-46A9-B89D-F5BBDB4249AF"
},
{
"criteria": "cpe:2.3:o:suse:suse_linux_enterprise_server:10:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A516C153-239B-4F41-88B4-8B8D4F92115C"
},
{
"criteria": "cpe:2.3:o:suse:suse_linux_enterprise_server:11:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE5FEEB4-95BC-47AF-A6EA-FEF4C2AF1A2C"
},
{
"criteria": "cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F691F4E7-2FF1-4EFB-B21F-E510049A9940"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DEE6B635-EDCF-4265-AAD5-9DAAD2872440",
"versionEndIncluding": "2.4.3",
"versionStartIncluding": "2.0.0"
},
{
"criteria": "cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53828E32-51DB-4C44-8CE2-5B056C3D67F2",
"versionEndExcluding": "3.3.0",
"versionStartIncluding": "3.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "product-security@apple.com"
}