CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
74552 | CVE-2014-7251 | Candidate | XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP2 allows local users to cause a denial of service (CPU or network traffic consumption) or read arbitrary files via unspecified vectors. | Assigned (20140930) | None (candidate not yet proposed) | View | |
75891 | CVE-2014-8590 | Candidate | XML external entity (XXE) vulnerability in the Web Service Navigator in SAP NetWeaver Application Server (AS) Java allows remote attackers to access arbitrary files via a crafted request. | Assigned (20141104) | None (candidate not yet proposed) | View | |
90833 | CVE-2016-4014 | Candidate | XML external entity (XXE) vulnerability in the UDDI component in SAP NetWeaver JAVA AS 7.4 allows remote attackers to cause a denial of service (system hang) via a crafted DTD in an XML request to uddi/api/replication, aka SAP Security Note 2254389. | Assigned (20160414) | None (candidate not yet proposed) | View | |
77513 | CVE-2015-0250 | Candidate | XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file. | Assigned (20141118) | None (candidate not yet proposed) | View | |
79109 | CVE-2015-1832 | Candidate | XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype. | Assigned (20150217) | None (candidate not yet proposed) | View |
Page 72 of 20943, showing 5 records out of 104715 total, starting on record 356, ending on 360