CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
93871 | CVE-2016-7051 | Candidate | XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD. | Assigned (20160823) | None (candidate not yet proposed) | View | |
50118 | CVE-2011-2206 | Candidate | XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than CVE-2011-1757. | Assigned (20110531) | None (candidate not yet proposed) | View | |
25250 | CVE-2007-1893 | Candidate | xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post." | Assigned (20070409) | None (candidate not yet proposed) | View | |
40060 | CVE-2009-2625 | Candidate | XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework. | Assigned (20090728) | None (candidate not yet proposed) | View | |
78114 | CVE-2015-0851 | Candidate | XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data. | Assigned (20150107) | None (candidate not yet proposed) | View |
Page 20876 of 20943, showing 5 records out of 104715 total, starting on record 104376, ending on 104380