Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Very High
CVE-2020-24590
Disclosure Date: August 21, 2020 (last updated February 22, 2025)
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
1
Attacker Value
Unknown
CVE-2020-11462
Disclosure Date: May 04, 2020 (last updated February 21, 2025)
An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interface enabled, it is possible to achieve a temporary DoS state of the management interface when sending an XML Entity Expansion (XEE) payload to the XMLRPC based RPC2 interface. The duration of the DoS state depends on available memory and CPU speed. The default restricted mode of the RPC2 interface is NOT vulnerable.
0
Attacker Value
Unknown
CVE-2020-3946
Disclosure Date: April 20, 2020 (last updated February 21, 2025)
InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 are vulnerable to Billion laughs attack (denial-of-service).
0
Attacker Value
Unknown
CVE-2020-2172
Disclosure Date: April 07, 2020 (last updated February 21, 2025)
Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
0
Attacker Value
Unknown
CVE-2012-6685
Disclosure Date: February 19, 2020 (last updated February 21, 2025)
Nokogiri before 1.5.4 is vulnerable to XXE attacks
0
Attacker Value
Unknown
CVE-2014-2228
Disclosure Date: February 19, 2020 (last updated February 21, 2025)
The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages.
0
Attacker Value
Unknown
CVE-2013-4335
Disclosure Date: February 07, 2020 (last updated February 21, 2025)
opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities
0
Attacker Value
Unknown
CVE-2020-6856
Disclosure Date: February 06, 2020 (last updated February 21, 2025)
An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of the XML documents that are used to specify the run-time settings of jobs and orders.
0
Attacker Value
Unknown
CVE-2019-20104
Disclosure Date: February 05, 2020 (last updated February 21, 2025)
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.
0
Attacker Value
Unknown
CVE-2020-5227
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
Feedgen (python feedgen) before 0.9.0 is susceptible to XML Denial of Service attacks. The *feedgen* library allows supplying XML as content for some of the available fields. This XML will be parsed and integrated into the existing XML tree. During this process, feedgen is vulnerable to XML Denial of Service Attacks (e.g. XML Bomb). This becomes a concern in particular if feedgen is used to include content from untrused sources and if XML (including XHTML) is directly included instead of providing plain tex content only. This problem has been fixed in feedgen 0.9.0 which disallows XML entity expansion and external resources.
0