VYPR

Flowdroid

by Secure Software Engineering

CVEs (1)

  • CVE-2021-32754MedJul 12, 2021
    risk 0.35cvss 5.3epss 0.01

    FlowDroid is a data flow analysis tool. FlowDroid versions prior to 2.9.0 contained an XML external entity (XXE) vulnerability that allowed an attacker who had control over the source/sink definition file in XML format to read files from external locations. In order for this to…