VYPR

Maven package

xerces/xercesImpl

pkg:maven/xerces/xercesImpl

Vulnerabilities (5)

  • CVE-2022-23437Jan 24, 2022
    affected < 2.12.2fixed 2.12.2

    There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerabili

  • CVE-2020-14338Sep 17, 2020
    affected < 2.12.0.sp3fixed 2.12.0.sp3

    A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certai

  • CVE-2012-0881HigOct 30, 2017
    affected < 2.12.0fixed 2.12.0

    Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.

  • CVE-2013-4002Jul 23, 2013
    affected < 2.12.0fixed 2.12.0

    XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java S

  • CVE-2009-2625Aug 6, 2009
    affected < 2.10.0fixed 2.10.0

    XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malfo