← Back

C3p0

c3p0

Vendor: Mchange • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Fedoraproject
MchangeOracle
11C3p0
Communications Ip Service ActivatorCommunications Session Route Manager+8 more
Sep 5, 2025
Apr 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
2Debian
Mchange
2C3p0
Debian Linux
Nov 21, 2024
Dec 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.