CVE List

Id CVE No. Status Description Phase Votes Comments Actions
74552  CVE-2014-7251  Candidate  XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP2 allows local users to cause a denial of service (CPU or network traffic consumption) or read arbitrary files via unspecified vectors.  Assigned (20140930)  None (candidate not yet proposed)    View
75891  CVE-2014-8590  Candidate  XML external entity (XXE) vulnerability in the Web Service Navigator in SAP NetWeaver Application Server (AS) Java allows remote attackers to access arbitrary files via a crafted request.  Assigned (20141104)  None (candidate not yet proposed)    View
90833  CVE-2016-4014  Candidate  XML external entity (XXE) vulnerability in the UDDI component in SAP NetWeaver JAVA AS 7.4 allows remote attackers to cause a denial of service (system hang) via a crafted DTD in an XML request to uddi/api/replication, aka SAP Security Note 2254389.  Assigned (20160414)  None (candidate not yet proposed)    View
77513  CVE-2015-0250  Candidate  XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.  Assigned (20141118)  None (candidate not yet proposed)    View
79109  CVE-2015-1832  Candidate  XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype.  Assigned (20150217)  None (candidate not yet proposed)    View

Page 72 of 20943, showing 5 records out of 104715 total, starting on record 356, ending on 360

Actions