VYPR

rpm package

opensuse/c3p0&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/c3p0&distro=openSUSE%20Tumbleweed

Vulnerabilities (4)

  • CVE-2026-55223MedJun 30, 2026
    affected < 0.14.1-1.1fixed 0.14.1-1.1

    c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC spec's DataSource.getConnection() and ConnectionPoolDataSource.getPooledConnection() match the getXXX

  • CVE-2026-27727CriFeb 25, 2026
    affected < 0.12.0-1.1fixed 0.12.0-1.1

    mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked within a running application. If an attack

  • CVE-2019-5427HigApr 22, 2019
    affected < 0.9.5.5-2.1fixed 0.9.5.5-2.1

    c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

  • CVE-2018-20433CriDec 24, 2018
    affected < 0.9.5.5-1.3fixed 0.9.5.5-1.3

    c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.