Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Very High

CVE-2020-24590

Disclosure Date: August 21, 2020 (last updated February 22, 2025)
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
Attacker Value
Unknown

CVE-2020-11462

Disclosure Date: May 04, 2020 (last updated February 21, 2025)
An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interface enabled, it is possible to achieve a temporary DoS state of the management interface when sending an XML Entity Expansion (XEE) payload to the XMLRPC based RPC2 interface. The duration of the DoS state depends on available memory and CPU speed. The default restricted mode of the RPC2 interface is NOT vulnerable.
Attacker Value
Unknown

CVE-2020-3946

Disclosure Date: April 20, 2020 (last updated February 21, 2025)
InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 are vulnerable to Billion laughs attack (denial-of-service).
Attacker Value
Unknown

CVE-2020-2172

Disclosure Date: April 07, 2020 (last updated February 21, 2025)
Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Attacker Value
Unknown

CVE-2012-6685

Disclosure Date: February 19, 2020 (last updated February 21, 2025)
Nokogiri before 1.5.4 is vulnerable to XXE attacks
Attacker Value
Unknown

CVE-2014-2228

Disclosure Date: February 19, 2020 (last updated February 21, 2025)
The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages.
Attacker Value
Unknown

CVE-2013-4335

Disclosure Date: February 07, 2020 (last updated February 21, 2025)
opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities
Attacker Value
Unknown

CVE-2020-6856

Disclosure Date: February 06, 2020 (last updated February 21, 2025)
An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of the XML documents that are used to specify the run-time settings of jobs and orders.
Attacker Value
Unknown

CVE-2019-20104

Disclosure Date: February 05, 2020 (last updated February 21, 2025)
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.
Attacker Value
Unknown

CVE-2020-5227

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
Feedgen (python feedgen) before 0.9.0 is susceptible to XML Denial of Service attacks. The *feedgen* library allows supplying XML as content for some of the available fields. This XML will be parsed and integrated into the existing XML tree. During this process, feedgen is vulnerable to XML Denial of Service Attacks (e.g. XML Bomb). This becomes a concern in particular if feedgen is used to include content from untrused sources and if XML (including XHTML) is directly included instead of providing plain tex content only. This problem has been fixed in feedgen 0.9.0 which disallows XML entity expansion and external resources.