Skip to main content

CWE archive

CWE-611 CVEs

Programmatic archive

1,270 CVEs tagged with CWE-611259 Critical, 567 High, 410 Medium, 34 Low, 0 Unrated.

CVE-2017-6323

Published Apr 16, 2018

The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is proc…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1308

Published Apr 9, 2018

This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImport…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1421

Published Apr 4, 2018

IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker c…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9116

Published Mar 29, 2018

An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and internal resources and potentially cause a Denial of Service.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-7461

Published Mar 20, 2018

XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cause a denial of service (memory…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3990

Published Mar 20, 2018

The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6225

Published Mar 15, 2018

An XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenticated user to expose a normally protected configuration scr…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-2401

Published Mar 14, 2018

SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML External Entity (XXE) vulnera…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000124

Published Mar 13, 2018

I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000090

Published Mar 13, 2018

textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the web server by exhausting serv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000069

Published Mar 13, 2018

FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5758

Published Mar 12, 2018

The Upload File functionality in upload.jspa in Aurea Jive Jive-n 9.0.2.1 On-Premises allows for an XML External Entity attack through a crafted file, allowing attackers to read a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0250

Published Mar 12, 2018

XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read ar…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0268

Published Mar 9, 2018

XML external entity (XXE) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Man…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7426

Published Mar 1, 2018

The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18197

Published Feb 24, 2018

In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated b…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-0369

Published Feb 21, 2018

XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated users to obtain sensitive information via crafted XML data.…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort
Showing 1,076-1,100 of 1,270 CVEsPage 44 of 51