CVE-2015-2776: Debian Linux

Medium severity, CVSS 4.3. EPSS: 2.4% chance of exploitation in the next 30 days.

The parse_SST function in FreeXL before 1.0.0i allows remote attackers to cause a denial of service (memory consumption) via a crafted shared strings table in a workbook.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Gaia-Gis Freexl: up to and including 1.0.0h

Published 2015-03-31. Last modified 2026-06-17.