CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93871  CVE-2016-7051  Candidate  XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.  Assigned (20160823)  None (candidate not yet proposed)    View
50118  CVE-2011-2206  Candidate  XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than CVE-2011-1757.  Assigned (20110531)  None (candidate not yet proposed)    View
25250  CVE-2007-1893  Candidate  xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."  Assigned (20070409)  None (candidate not yet proposed)    View
40060  CVE-2009-2625  Candidate  XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.  Assigned (20090728)  None (candidate not yet proposed)    View
78114  CVE-2015-0851  Candidate  XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.  Assigned (20150107)  None (candidate not yet proposed)    View

Page 20876 of 20943, showing 5 records out of 104715 total, starting on record 104376, ending on 104380

Actions