Skip to main content

Vendor/product archive

apache / xerces-c++ CVEs

Beta · best-effort

11 CVEs tagged to apache / xerces-c++3 Critical, 5 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-23807

Published Feb 29, 2024

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1311

Published Dec 18, 2019

The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained ve…

CVSS 8.1 · High

CVE-2017-12627

Published Mar 1, 2018

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0880

Published Aug 8, 2017

Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes hash table collisions.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2099

Published May 13, 2016

Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1885

Published Aug 11, 2009

Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4482

Published Oct 8, 2008

The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML schema definition with a large m…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1575

Published Dec 31, 2004

The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1