Total
1035 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-1000829 | 1 Anyplace Project | 1 Anyplace | 2024-11-21 | 6.8 MEDIUM | 9.0 CRITICAL |
Anyplace version before commit 80359b4 contains a XML External Entity (XXE) vulnerability in Man in the middle on map API call that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 80359b4. | |||||
CVE-2018-1000828 | 1 Frostwire | 1 Frostwire | 2024-11-21 | 6.8 MEDIUM | 9.0 CRITICAL |
FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the middle the call to update the software. | |||||
CVE-2018-1000825 | 1 Freecol | 1 Freecol | 2024-11-21 | 7.5 HIGH | 10.0 CRITICAL |
FreeCol version <= nightly-2018-08-22 contains a XML External Entity (XXE) vulnerability in FreeColXMLReader parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Freecol file. | |||||
CVE-2018-1000823 | 1 Exist-db | 1 Exist | 2024-11-21 | 7.5 HIGH | 10.0 CRITICAL |
exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. | |||||
CVE-2018-1000822 | 1 Codelibs | 1 Fess | 2024-11-21 | 7.5 HIGH | 10.0 CRITICAL |
codelibs fess version before commit faa265b contains a XML External Entity (XXE) vulnerability in GSA XML file parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via specially crafted GSA XML files. This vulnerability appears to have been fixed in after commit faa265b. | |||||
CVE-2018-1000821 | 1 Micromathematics Project | 1 Micromathematics | 2024-11-21 | 7.5 HIGH | 10.0 CRITICAL |
MicroMathematics version before commit 5c05ac8 contains a XML External Entity (XXE) vulnerability in SMathStudio files that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Specially crafted SMathStudio files. This vulnerability appears to have been fixed in after commit 5c05ac8. | |||||
CVE-2018-1000820 | 1 Neo4j | 1 Awesome Procedures On Cyper | 2024-11-21 | 7.5 HIGH | 10.0 CRITICAL |
neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c. | |||||
CVE-2018-1000652 | 1 Jabref | 1 Jabref | 2024-11-21 | 7.5 HIGH | 10.0 CRITICAL |
JabRef version <=4.3.1 contains a XML External Entity (XXE) vulnerability in MsBibImporter XML Parser that can result in disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted MsBib file. This vulnerability appears to have been fixed in after commit 89f855d. | |||||
CVE-2018-1000651 | 1 Gchq | 1 Stroom | 2024-11-21 | 7.5 HIGH | 10.0 CRITICAL |
Stroom version <5.4.5 contains a XML External Entity (XXE) vulnerability in XML Parser that can result in disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted XML file. | |||||
CVE-2018-1000644 | 1 Eclipse | 1 Rdf4j | 2024-11-21 | 7.5 HIGH | 10.0 CRITICAL |
Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in the disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted RDF file. | |||||
CVE-2018-1000639 | 1 Latexdraw Project | 1 Latexdraw | 2024-11-21 | 6.8 MEDIUM | 9.6 CRITICAL |
LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file. | |||||
CVE-2018-1000616 | 1 Onosproject | 1 Onos | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConfigParser.java loadxml() that can result in An adversary can remotely launch XXE attacks on ONOS controller via an OpenConfig Terminal Device.. This attack appear to be exploitable via network connectivity. | |||||
CVE-2018-1000614 | 1 Onosproject | 1 Onos | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/org/onosproject/provider/netconf/alarm/NetconfAlarmTranslator.java that can result in An adversary can remotely launch advanced XXE attacks on ONOS controller without authentication.. This attack appear to be exploitable via crafted protocol message. | |||||
CVE-2018-1000548 | 1 Umlet | 1 Umlet | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
Umlet version < 14.3 contains a XML External Entity (XXE) vulnerability in File parsing that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted UXF file. This vulnerability appears to have been fixed in 14.3. | |||||
CVE-2018-1000546 | 1 Triplea-game | 1 Triplea | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
Triplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE) vulnerability in Importing game data that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted game data file (XML). | |||||
CVE-2018-1000542 | 1 Netbeans-mmd-plugin Project | 1 Netbeans-mmd-plugin | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
netbeans-mmd-plugin version <= 1.4.3 contains a XML External Entity (XXE) vulnerability in MMD file import that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted MMD file. | |||||
CVE-2018-1000540 | 1 Loboevolution Project | 1 Loboevolution | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
LoboEvolution version < 9b75694cedfa4825d4a2330abf2719d470c654cd contains a XML External Entity (XXE) vulnerability in XML Parsing when viewing the XML file in the browser that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted XML file. | |||||
CVE-2018-1000515 | 1 News-articles Project | 1 News-articles | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
ventrian News-Articles version NewsArticles.00.09.11 contains a XML External Entity (XXE) vulnerability in News-Articles/API/MetaWebLog/Handler.ashx.vb that can result in Attacker can read any file in the server or use smbrelay attack to access to server.. | |||||
CVE-2018-1000198 | 1 Jenkins | 1 Black Duck Hub | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
A XML external entity processing vulnerability exists in Jenkins Black Duck Hub Plugin 3.1.0 and older in PostBuildScanDescriptor.java that allows attackers with Overall/Read permission to make Jenkins process XML eternal entities in an XML document. | |||||
CVE-2018-1000124 | 1 I-librarian | 1 I\, Librarian | 2024-11-21 | 7.5 HIGH | 10.0 CRITICAL |
I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting xml in the Parameter form_import_textarea. |