AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-4434

HIGH · CVSS 7.8 EPSS 3.45%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-09-30 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2016-4434
Severity
HIGH
CVSS
7.8
EPSS
3.45%
Apache

Original NVD Description

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.