Vulnerabilities > Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

DATE CVE VULNERABILITY TITLE RISK
2024-02-04 CVE-2023-52426 XML Entity Expansion vulnerability in Libexpat Project Libexpat
libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.
local
low complexity
libexpat-project CWE-776
5.5
2023-12-07 CVE-2023-49967 XML Entity Expansion vulnerability in Typecho 1.2.1
Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.
network
low complexity
typecho CWE-776
7.5
2023-08-31 CVE-2023-41635 XML Entity Expansion vulnerability in Grupposcai Realgimm 1.1.37
A XML External Entity (XXE) vulnerability in the VerifichePeriodiche.aspx component of GruppoSCAI RealGimm v1.1.37p38 allows attackers to read any file in the filesystem via supplying a crafted XML file.
network
low complexity
grupposcai CWE-776
6.5
2023-08-08 CVE-2023-3569 XML Entity Expansion vulnerability in Phoenixcontact products
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.
network
low complexity
phoenixcontact CWE-776
4.9
2023-07-27 CVE-2023-38490 XML Entity Expansion vulnerability in Getkirby Kirby
Kirby is a content management system.
network
low complexity
getkirby CWE-776
critical
10.0
2023-03-20 CVE-2023-28118 XML Entity Expansion vulnerability in Kaml Project Kaml
kaml provides YAML support for kotlinx.serialization.
network
low complexity
kaml-project CWE-776
7.5
2023-03-01 CVE-2023-20052 XML Entity Expansion vulnerability in multiple products
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to enabling XML entity substitution that may result in XML external entity injection.
network
low complexity
cisco clamav stormshield CWE-776
5.3
2022-11-18 CVE-2022-44641 XML Entity Expansion vulnerability in multiple products
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial of Service.
network
low complexity
linaro debian CWE-776
6.5
2022-10-11 CVE-2022-34430 XML Entity Expansion vulnerability in Dell Hybrid Client
Dell Hybrid Client below 1.8 version contains a Zip Bomb Vulnerability in UI.
network
low complexity
dell CWE-776
7.5
2022-08-30 CVE-2022-25857 XML Entity Expansion vulnerability in multiple products
The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.
network
low complexity
snakeyaml-project debian CWE-776
7.5