Vulnerability index

Browse CVEs

70 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Cxf HIGH 7.5
CVE-2016-8739EPSS 7%

The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apach…

Fix: after 3.0.11
Fix from $1,950 2017-08-10
Wink HIGH 7.4
CVE-2010-2245EPSS 12%

XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service…

Fix: after 1.1.1
Fix from $1,950 2017-08-08
Sling CRITICAL 9.8
CVE-2016-6798

In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string…

Fix: after 1.0.10
Fix from $2,300 2017-07-19
Openmeetings CRITICAL 10.0
CVE-2017-7664

Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.

Mitigation only
Fix from $2,300 2017-07-17
Formatting Objects Processor HIGH 7.3
CVE-2017-5661

In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed S…

Fix: after 2.1
Fix from $1,950 2017-04-18
Batik HIGH 7.3
CVE-2017-5662

In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously form…

Fix: after 1.8
Fix from $1,950 2017-04-18
Ignite MEDIUM 5.9
CVE-2016-6805

Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.

Fix: after 1.8
Fix from $1,600 2017-04-07
Derby CRITICAL 9.1
CVE-2015-1832EPSS 12%

XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows…

Mitigation only
Fix from $2,300 2016-10-03
Poi MEDIUM 5.5
CVE-2016-5000

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external …

Fix: after 3.13
Fix from $1,600 2016-08-05
Openoffice MEDIUM 6.5
CVE-2012-0037EPSS 14%

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other produ…

Patch available
Fix from $1,600 2012-06-17