Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 8.1 CVE-2016-8980 IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remo… License Metric Tool Mitigation only Fix from $1,9502017-02-01 HIGH 8.1 CVE-2016-6059 IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML da… Infosphere Datastage Patch available Fix from $1,9502017-02-01 CRITICAL 9.1 CVE-2016-2908 IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when proces… Security Access Manager 9.0 Firmware Patch available Fix from $2,3002017-02-01 MEDIUM 6.5 CVE-2016-3027 IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML … Security Access Manager 9.0 Firmware Patch available Fix from $1,6002017-02-01 MEDIUM 6.5 CVE-2015-7743 XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creat… Prtg Network Monitor after 14.4.12.3282 Fix from $1,6002017-01-23 HIGH 7.5 CVE-2016-10097 XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbi… Openam Mitigation only Fix from $1,9502017-01-02 MEDIUM 5.8 CVE-2016-7458 VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document c… Vsphere Client Mitigation only Fix from $1,6002016-12-29 HIGH 7.7 CVE-2016-7459 VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distribu… Vcenter Server Patch available Fix from $1,9502016-12-29 CRITICAL 9.1 CVE-2016-7460 The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attacker… Vrealize Automation Mitigation only Fix from $2,3002016-12-29 CRITICAL 9.1 CVE-2016-9180 perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entitie… Xml Twig For Perl Mitigation only Fix from $2,3002016-12-22 HIGH 7.1 CVE-2016-9181 perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processe… Image Info For Perl Mitigation only Fix from $1,9502016-12-22 HIGH 8.8 CVE-2016-5851 python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document. Python Docx after 0.8.5 Fix from $1,9502016-12-21 HIGH 8.1 CVE-2016-3055 IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory cons… Filenet Workplace Patch available Fix from $1,9502016-12-01 HIGH 8.1 CVE-2016-3033 IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) vi… Appscan Source Mitigation only Fix from $1,9502016-12-01 MEDIUM 5.4 CVE-2016-0284 The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 bef… Rational Software Architect Design Manager Mitigation only Fix from $1,6002016-11-24 MEDIUM 6.5 CVE-2016-9563 KEVEPSS 24% BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~hi… Netweaver Application Server Java Mitigation only Fix from $1,6002016-11-23 MEDIUM 5.5 CVE-2016-9318 libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current docume… Ubuntu Linux after 2.9.4 Fix from $1,6002016-11-16 CRITICAL 9.1 CVE-2015-1832EPSS 12% XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows… Derby Mitigation only Fix from $2,3002016-10-03 HIGH 7.1 CVE-2016-5971 IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or … Security Privileged Identity Manager Virtual Appliance after 2.0.2 Fix from $1,9502016-09-26 HIGH 7.5 CVE-2016-6408 Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction w… Prime Home Mitigation only Fix from $1,9502016-09-24 HIGH 8.6 CVE-2016-4264EPSS 69% The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files o… Coldfusion after 11.0 Fix from $1,9502016-09-01 MEDIUM 5.5 CVE-2016-5000 The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external … Poi after 3.13 Fix from $1,6002016-08-05 CRITICAL 9.6 CVE-2015-8866 ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader… PHP 5.5.22 / 5.6.6+ Fix from $2,3002016-05-22 CRITICAL 9.1 CVE-2016-3974EPSS 15% XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denia… Netweaver Application Server Java after 7.50 Fix from $2,3002016-04-07 MEDIUM 5.0 CVE-2015-3451 The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML exter… Xml Libxml after 2.0118 Fix from $1,6002015-05-12 MEDIUM 6.8 CVE-2013-6429EPSS 90% The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolut… Spring Framework after 3.2.4 Fix from $1,6002014-01-26 MEDIUM 6.8 CVE-2013-0340EPSS 19% expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, wh… Python 2.4.0 / 3.6.15+ Fix from $1,6002014-01-21 HIGH 7.5 CVE-2013-1915 ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU a… Fedora 2.7.3+ Fix from $1,9502013-04-25 CRITICAL 9.1 CVE-2012-3363EPSS 50% Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote atta… Fedora 1.11.12+ Fix from $2,3002013-02-13 MEDIUM 5.5 CVE-2012-5656 The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML exter… Fedora 0.48.4+ Fix from $1,6002013-01-18