Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2017-07-11 CVE-2017-0170 XXE vulnerability in Microsoft products
Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability due to the way it parses XML input, aka "Windows Performance Monitor Information Disclosure Vulnerability".
network
low complexity
microsoft CWE-611
6.5
2017-07-05 CVE-2017-1254 XXE vulnerability in IBM Security Guardium
IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1
2017-06-30 CVE-2017-10670 XXE vulnerability in Xoev Osci Transport Library 1.6/1.6.1
An XML External Entity (XXE) issue exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET), exploitable by sending a crafted standard-conforming OSCI message from within the infrastructure.
network
low complexity
xoev CWE-611
critical
9.8
2017-06-27 CVE-2017-1322 XXE vulnerability in IBM API Connect
IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
8.2
2017-06-26 CVE-2017-6662 XXE vulnerability in Cisco products
A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected system as well as perform remote code execution.
network
low complexity
cisco CWE-611
8.0
2017-06-16 CVE-2017-9231 XXE vulnerability in Citrix Xenmobile Server
XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors.
network
low complexity
citrix CWE-611
7.5
2017-06-08 CVE-2016-9698 XXE vulnerability in IBM Rational Rhapsody Design Manager
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data.
network
low complexity
ibm CWE-611
8.1
2017-06-07 CVE-2016-0254 XXE vulnerability in IBM Cognos Business Intelligence
IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data.
network
low complexity
ibm CWE-611
6.5
2017-06-07 CVE-2015-7326 XXE vulnerability in Milton Webdav
XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3.
network
low complexity
milton CWE-611
critical
9.8
2017-05-30 CVE-2017-2308 XXE vulnerability in Juniper Junos Space
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
network
low complexity
juniper CWE-611
6.5