CVE-2012-5656

5.5
MEDIUMCVSS v3.1 Base Score
1.16%
LOW RiskEPSS (66th percentile)

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

Published: 1/18/2013
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS v2 Score

2.1

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS Score (Exploitation Probability)

1.16%LOW Exploitation Risk
66th percentile

This vulnerability has a 1.16% probability of being exploited in the next 30 days, ranking higher than 66% of all scored CVEs.

CWE Classification

Advertisement