xerces/xerces 2.4.0 | Vulnerabilities | Sonatype Guide
xerces 2.4.0
Overview
Latest Version: xerces
Published: Nov 22, 2005
Policy Compliance
Developer Trust Score: N/A
Recommended Version: x.y.z
Recommended upgrade that meets your policy.
Versions
- 9 Versions available
Vulnerabilities
- 5 Vulnerabilities found
Dependencies
- 0 Dependencies
Severity Breakdown
- Critical: 0
- High: 2
- Medium: 0
- Low: 0
CVSS Score
- 0.0
EPSS Score
- 0.0
Malware Status
- All
Vulnerability Details
-
- Severity: High
- Published: Nov 2, 2017
- Description: Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
-
- Severity: High
- Published: Mar 28, 2017
- Description: XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service via vectors related to XML attribute names.