# xerces 2.4.0

## Overview

- **Latest Version**: xerces
- **Published**: Nov 22, 2005
- **Policy Compliance**
- **Developer Trust Score**: N/A

- **Recommended Version**: [x.y.z](https://guide.sonatype.com/component/maven/xerces%3Axerces/x.y.z)  
  Recommended upgrade that meets your policy.
- **[Compare Versions](https://guide.sonatype.com/component/maven/xerces%3Axerces/2.4.0/versions)**

## Versions
- 9 Versions available

## Vulnerabilities
- 5 Vulnerabilities found

## Dependencies
- 0 Dependencies

### Severity Breakdown
- **Critical**: 0  
- **High**: 2  
- **Medium**: 0  
- **Low**: 0

### CVSS Score
- 0.0

### EPSS Score
- 0.0

### Malware Status
- All

## Vulnerability Details

1. **[CVE-2012-0881](https://guide.sonatype.com/vulnerability/CVE-2012-0881)**  
   - **Severity**: High  
   - **Published**: Nov 2, 2017  
   - **Description**: Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.

2. **[CVE-2013-4002](https://guide.sonatype.com/vulnerability/CVE-2013-4002)**  
   - **Severity**: High  
   - **Published**: Mar 28, 2017  
   - **Description**: XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service via vectors related to XML attribute names.
