NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 28337 | CVE-2015-7942 | The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 41227 | CVE-2013-6025 | The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to read arbitrary files via a SQL statement containing an XML document with an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 2 | 4 | Medium | 2017-01-18 | 2013-10-30 | View | |
| 18110 | CVE-2016-1762 | The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. | 2 | 10 | High | 2017-01-19 | 2016-12-27 | View | |
| 28484 | CVE-2015-8241 | The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data. | 2 | 6.4 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 34603 | CVE-2014-7146 | The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or (2) issuelink attribute in an XML file, which is not properly handled when executing the preg_replace function with the e modifier. | 2 | 7.5 | High | 2017-01-19 | 2017-01-02 | View |
Page 2591 of 17672, showing 5 records out of 88360 total, starting on record 12951, ending on 12955