Xerces-c\+\+
This hub aggregates every CVE we track for Xerces-c\+\+, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
11
CVEs tracked
3
Critical
5
High
0
In CISA KEV
Severity distribution
HIGH5MEDIUM3CRITICAL3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 11 most recently published vulnerabilities affecting Xerces-c\+\+.
- CVE-2024-23807Apache Xerces C++: Use-after-free on external DTD scan9.8
- CVE-2023-37536HCL BigFix Platform is vulnerable to an integer overflow in xerces-c++ 3.2.38.2
- CVE-2018-1311The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the libra...8.1
- CVE-2017-12627In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.9.8
- CVE-2012-0880Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes hash table collisions.7.5
- CVE-2016-4463Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.7.5
- CVE-2016-2099Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid character in an XML...9.8
- CVE-2015-0252internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.5.0
- CVE-2009-1885Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors...4.3
- CVE-2008-4482The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML schema definition with a large maxOccurs value, wh...7.8
- CVE-2004-1575The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.5.0
Product normalization is registry-driven with AI assist and human review. How it works