VYPR
Vendor

Mpxj

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2020-35460MedDec 14, 2020
    risk 0.28cvss 5.3epss 0.02

    common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.

  • CVE-2022-41954LowNov 25, 2022
    risk 0.14cvss 3.3epss 0.00

    MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-like operating systems (not Windows or macos), MPXJ's use of `File.createTempFile(..)` results in temporary files being created with the permissions `-rw-r--r--`.…

  • CVE-2020-25020CriAug 29, 2020
    risk 0.00cvss 9.8epss 0.03

    MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.