Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2018-01-16 CVE-2016-0219 XXE vulnerability in IBM products
XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote authenticated users to cause a denial of service via crafted XML data.
network
low complexity
ibm CWE-611
6.5
2018-01-09 CVE-2017-1666 XXE vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
8.1
2018-01-03 CVE-2017-1000477 XXE vulnerability in Xmlbundle Project Xmlbundle 0.1.7
XMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks.
network
low complexity
xmlbundle-project CWE-611
7.5
2018-01-03 CVE-2017-1000498 XXE vulnerability in Androidsvg Project Androidsvg 1.2.2
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
local
low complexity
androidsvg-project CWE-611
7.8
2018-01-03 CVE-2017-1000497 XXE vulnerability in Pepperminty-Wiki Project Pepperminty-Wiki 0.15
Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code execution
network
low complexity
pepperminty-wiki-project CWE-611
critical
9.8
2018-01-03 CVE-2017-1000496 XXE vulnerability in Commsy 9.0.0
Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execution of code.
network
low complexity
commsy CWE-611
8.8
2017-12-29 CVE-2014-3630 XXE vulnerability in multiple products
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
network
low complexity
playframework lightbend CWE-611
critical
9.8
2017-12-15 CVE-2017-14101 XXE vulnerability in Changehealthcare Conserus Image Repository 2.1.1.105
A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company.
network
low complexity
changehealthcare CWE-611
critical
9.8
2017-12-01 CVE-2017-11286 XXE vulnerability in Adobe Coldfusion 11.0/2016
Adobe ColdFusion has an XML external entity (XXE) injection vulnerability.
network
low complexity
adobe CWE-611
7.5
2017-11-30 CVE-2017-14949 XXE vulnerability in Restlet
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered.
network
low complexity
restlet CWE-611
7.5