Skip to main content

CWE archive

CWE-611 CVEs

Programmatic archive

1,288 CVEs tagged with CWE-611260 Critical, 576 High, 418 Medium, 34 Low, 0 Unrated.

CVE-2012-2239

Published Nov 24, 2012

Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as de…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-4399

Published Oct 9, 2012

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-3489

Published Oct 3, 2012

The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2012-0037

Published Jun 17, 2012

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remo…

CVSS 6.5 · Medium

CVE-2010-3322

Published Sep 14, 2010

The XML parser in Splunk 4.0.0 through 4.1.4 allows remote authenticated users to obtain sensitive information and gain privileges via an XML External Entity (XXE) attack to unkno…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1306

Published Jun 15, 2005

The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML E…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,276-1,288 of 1,288 CVEsPage 52 of 52