Vulnerabilities (CVE)

Filtered by vendor Mchange Subscribe
Filtered by product C3p0
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-5427 3 Fedoraproject, Mchange, Oracle 11 Fedora, C3p0, Communications Ip Service Activator and 8 more 2024-02-28 5.0 MEDIUM 7.5 HIGH
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
CVE-2018-20433 2 Debian, Mchange 2 Debian Linux, C3p0 2024-02-28 7.5 HIGH 9.8 CRITICAL
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.