xerces:xercesImpl
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting xerces:xercesImplpage 1 of 1
- CVE-2009-2625NONECVSS 0.0EG 0.0✓ Fixed in 2.10.02009-08-06
vulnerable: 2.0.0 ... 2.9.1 (15 versions)
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infi…
- CVE-2012-0881HIGHCVSS 7.5EG 7.5✓ Fixed in 2.12.02017-10-30
vulnerable: 2.0.0 ... 2.9.1 (17 versions)
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
- CVE-2013-4002NONECVSS 0.0EG 0.0✓ Fixed in 2.12.02013-07-23
vulnerable: 2.0.0 ... 2.9.1 (17 versions)
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and …
- CVE-2020-14338MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.12.0.sp32020-09-17
vulnerable: 2.0.0 ... 2.9.1 (17 versions)
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to ma…
- CVE-2022-23437MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.12.22022-01-24
vulnerable: 2.0.0 ... 2.9.1 (19 versions)
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources…
Check whether xerces:xercesImpl is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for xerces:xercesImpl CVEs against the assets you own.
Start Free Scan →