Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
License Metric Tool HIGH 8.1
CVE-2016-8980

IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remo…

Mitigation only
Fix from $1,950 2017-02-01
Infosphere Datastage HIGH 8.1
CVE-2016-6059

IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML da…

Patch available
Fix from $1,950 2017-02-01
Security Access Manager 9.0 Firmware CRITICAL 9.1
CVE-2016-2908

IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when proces…

Patch available
Fix from $2,300 2017-02-01
Security Access Manager 9.0 Firmware MEDIUM 6.5
CVE-2016-3027

IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML …

Patch available
Fix from $1,600 2017-02-01
Prtg Network Monitor MEDIUM 6.5
CVE-2015-7743

XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creat…

Fix: after 14.4.12.3282
Fix from $1,600 2017-01-23
Openam HIGH 7.5
CVE-2016-10097

XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbi…

Mitigation only
Fix from $1,950 2017-01-02
Vsphere Client MEDIUM 5.8
CVE-2016-7458

VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document c…

Mitigation only
Fix from $1,600 2016-12-29
Vcenter Server HIGH 7.7
CVE-2016-7459

VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distribu…

Patch available
Fix from $1,950 2016-12-29
Vrealize Automation CRITICAL 9.1
CVE-2016-7460

The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attacker…

Mitigation only
Fix from $2,300 2016-12-29
Xml Twig For Perl CRITICAL 9.1
CVE-2016-9180

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entitie…

Mitigation only
Fix from $2,300 2016-12-22
Image Info For Perl HIGH 7.1
CVE-2016-9181

perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processe…

Mitigation only
Fix from $1,950 2016-12-22
Python Docx HIGH 8.8
CVE-2016-5851

python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document.

Fix: after 0.8.5
Fix from $1,950 2016-12-21
Filenet Workplace HIGH 8.1
CVE-2016-3055

IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory cons…

Patch available
Fix from $1,950 2016-12-01
Appscan Source HIGH 8.1
CVE-2016-3033

IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) vi…

Mitigation only
Fix from $1,950 2016-12-01
Rational Software Architect Design Manager MEDIUM 5.4
CVE-2016-0284

The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 bef…

Mitigation only
Fix from $1,600 2016-11-24
Netweaver Application Server Java MEDIUM 6.5
CVE-2016-9563 KEVEPSS 24%

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~hi…

Mitigation only
Fix from $1,600 2016-11-23
Ubuntu Linux MEDIUM 5.5
CVE-2016-9318

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current docume…

Fix: after 2.9.4
Fix from $1,600 2016-11-16
Derby CRITICAL 9.1
CVE-2015-1832EPSS 12%

XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows…

Mitigation only
Fix from $2,300 2016-10-03
Security Privileged Identity Manager Virtual Appliance HIGH 7.1
CVE-2016-5971

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or …

Fix: after 2.0.2
Fix from $1,950 2016-09-26
Prime Home HIGH 7.5
CVE-2016-6408

Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction w…

Mitigation only
Fix from $1,950 2016-09-24
Coldfusion HIGH 8.6
CVE-2016-4264EPSS 69%

The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files o…

Fix: after 11.0
Fix from $1,950 2016-09-01
Poi MEDIUM 5.5
CVE-2016-5000

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external …

Fix: after 3.13
Fix from $1,600 2016-08-05
PHP CRITICAL 9.6
CVE-2015-8866

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader…

Fix: 5.5.22 / 5.6.6+
Fix from $2,300 2016-05-22
Netweaver Application Server Java CRITICAL 9.1
CVE-2016-3974EPSS 15%

XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denia…

Fix: after 7.50
Fix from $2,300 2016-04-07
Xml Libxml MEDIUM 5.0
CVE-2015-3451

The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML exter…

Fix: after 2.0118
Fix from $1,600 2015-05-12
Spring Framework MEDIUM 6.8
CVE-2013-6429EPSS 90%

The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolut…

Fix: after 3.2.4
Fix from $1,600 2014-01-26
Python MEDIUM 6.8
CVE-2013-0340EPSS 19%

expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, wh…

Fix: 2.4.0 / 3.6.15+
Fix from $1,600 2014-01-21
Fedora HIGH 7.5
CVE-2013-1915

ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU a…

Fix: 2.7.3+
Fix from $1,950 2013-04-25
Fedora CRITICAL 9.1
CVE-2012-3363EPSS 50%

Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote atta…

Fix: 1.11.12+
Fix from $2,300 2013-02-13
Fedora MEDIUM 5.5
CVE-2012-5656

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML exter…

Fix: 0.48.4+
Fix from $1,600 2013-01-18