CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91131  CVE-2016-4312  Candidate  XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to XACML features to read arbitrary files, cause a denial of service, conduct server-side request forgery (SSRF) attacks, or have unspecified other impact via a crafted XACML request to entitlement/eval-policy-submit.jsp. NOTE: this issue can be combined with CVE-2016-4311 to exploit the vulnerability without credentials.  Assigned (20160427)  None (candidate not yet proposed)    View
77526  CVE-2015-0263  Candidate  XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.  Assigned (20141118)  None (candidate not yet proposed)    View
70925  CVE-2014-3629  Candidate  XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0.30 allows remote attackers to cause outgoing HTTP connections via a crafted message.  Assigned (20140514)  None (candidate not yet proposed)    View
91268  CVE-2016-4449  Candidate  XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.  Assigned (20160502)  None (candidate not yet proposed)    View
90539  CVE-2016-3720  Candidate  XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.  Assigned (20160330)  None (candidate not yet proposed)    View

Page 20873 of 20943, showing 5 records out of 104715 total, starting on record 104361, ending on 104365

Actions