CWE-611
1,244 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,244)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Openmrs 2Html Form Entry Reference ApplicationNov 21, 2024 Sep 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0. |
1Pdf Xchange 1Pdf Xchange Editor Nov 27, 2024 Sep 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PDF-XChange Editor through 7.0.326.1 allows remote attackers to cause a denial of service (resource consumption) via a crafted x:xmpmeta structure, a related issue to CVE-2003-1564. |
1Xovis 3Pc2 Firmware Pc2r FirmwarePc3 FirmwareNov 21, 2024 Aug 30, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow XXE. |
2Broadcom Ca2Project Portfolio Management Project Portfolio ManagementNov 21, 2024 Aug 30, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to conduct server side request forgery attacks. |
2Broadcom Ca2Project Portfolio Management Project Portfolio ManagementNov 21, 2024 Aug 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to access sensitive information. |
XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx. |
This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shipped with Apache Cayenne and intended for editing Cayenne ORM models store...Show more |
JabRef version <=4.3.1 contains a XML External Entity (XXE) vulnerability in MsBibImporter XML Parser that can result in disclosure of confidential data, denial of service, server side request forgery, port scanning. Thi...Show more |
Stroom version <5.4.5 contains a XML External Entity (XXE) vulnerability in XML Parser that can result in disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear...Show more |
Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in the disclosure of confidential data, denial of service, server side re...Show more |
1Latexdraw Project 1Latexdraw Nov 21, 2024 Aug 20, 2018 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear...Show more |
In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1)...Show more |
In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) A...Show more |
1Dell 2Emc Data Protection Advisor Emc Integrated Data Protection ApplianceNov 21, 2024 Aug 10, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XML External Entity (XXE) Injection vulnerability in the REST API. An aut...Show more |
1Tibco 2Activematrix Businessworks Activematrix Businessworks Distribution For Tibco Silver FabricNov 21, 2024 Aug 8, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric contai...Show more |
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on external systems. If an unprivileged user...Show more |
1Ocsinventory Ng 1Ocsinventory Ng Nov 21, 2024 Aug 4, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a...Show more |
1Spirton 1Universal Media Server Nov 21, 2024 Aug 3, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to:...Show more |
IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml. |
1Sap 1Business Planning And Consolidation Nov 21, 2024 Aug 2, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML external entity to be referenced, resulting in information disclosure an...Show more |