Critical severity10.0OSV Advisory· Published Dec 20, 2018· Updated Jun 17, 2026
CVE-2018-1000835
CVE-2018-1000835
Description
KeePassDX version <= 2.5.0.0beta17 contains a XML External Entity (XXE) vulnerability in kdbx file parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta1:*:*:*:*:*:*+ 16 more
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta10:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta11:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta12:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta13:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta14:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta15:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta16:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta17:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta8:*:*:*:*:*:*
- cpe:2.3:a:keepassdx:keepass_dx:2.5.0.0:beta9:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- 0dd.zone/2018/10/28/KeePassDX-XXE/nvdThird Party Advisory
- github.com/Kunzisoft/KeePassDX/issues/200nvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.