Vulnerabilities > Mchange > C3P0

DATE CVE VULNERABILITY TITLE RISK
2019-04-22 CVE-2019-5427 XML Entity Expansion vulnerability in multiple products
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
network
low complexity
mchange fedoraproject oracle CWE-776
7.5
2018-12-24 CVE-2018-20433 XXE vulnerability in multiple products
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
network
low complexity
mchange debian CWE-611
critical
9.8