Vulnerabilities (CVE)

Filtered by CWE-611
Total 998 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-10799 1 Svglib Project 1 Svglib 2020-03-24 7.5 HIGH 9.8 CRITICAL
The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.
CVE-2020-9044 1 Johnsoncontrols 20 Metasys Application And Data Server, Metasys Extended Application And Data Server, Metasys Lonworks Control Server and 17 more 2020-03-11 6.4 MEDIUM 9.1 CRITICAL
XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Server (ADS, ADS-Lite) versions 10.1 and prior; Metasys Extended Application and Data Server (ADX) versions 10.1 and prior; Metasys Open Data Server (ODS) versions 10.1 and prior; Metasys Open Application Server (OAS) version 10.1; Metasys Network Automation Engine (NAE55 only) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys Network Integration Engine (NIE55/NIE59) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys NAE85 and NIE85 versions 10.1 and prior; Metasys LonWorks Control Server (LCS) versions 10.1 and prior; Metasys System Configuration Tool (SCT) versions 13.2 and prior; Metasys Smoke Control Network Automation Engine (NAE55, UL 864 UUKL/ORD-C100-13 UUKLC 10th Edition Listed) version 8.1.
CVE-2015-7968 1 Sap 1 Netweaver Application Server 2020-03-10 4.0 MEDIUM 4.3 MEDIUM
nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI.
CVE-2019-6194 1 Lenovo 1 Xclarity Administrator 2020-02-21 4.3 MEDIUM 5.5 MEDIUM
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure.
CVE-2020-6187 1 Sap 1 Netweaver Guided Procedures 2020-02-19 4.0 MEDIUM 4.9 MEDIUM
SAP NetWeaver (Guided Procedures), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document input from a compromised admin, leading to Denial of Service.
CVE-2020-1975 1 Paloaltonetworks 1 Pan-os 2020-02-18 6.5 MEDIUM 8.8 HIGH
Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This issue affects PAN-OS 8.1 versions earlier than PAN-OS 8.1.12 and PAN-OS 9.0 versions earlier than PAN-OS 9.0.6. This issue does not affect PAN-OS 7.1, PAN-OS 8.0, or PAN-OS 9.1 or later versions.
CVE-2017-9458 1 Paloaltonetworks 1 Pan-os 2020-02-17 7.5 HIGH 9.8 CRITICAL
XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive information, cause a denial of service, or conduct server-side request forgery (SSRF) attacks via unspecified vectors.
CVE-2014-2052 1 Owncloud 1 Owncloud 2020-02-12 7.5 HIGH 9.8 CRITICAL
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
CVE-2013-4334 1 Tejimaya 1 Opwebapiplugin 2020-02-11 7.5 HIGH 9.8 CRITICAL
opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities
CVE-2019-12331 1 Phpspreadsheet Project 1 Phpspreadsheet 2020-02-10 6.8 MEDIUM 8.8 HIGH
PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if something else than UTF-8 is declared in the header. This was a security measurement to prevent CVE-2018-19277 but the fix is not sufficient. By double-encoding the the xml payload to utf-7 it is possible to bypass the check for the string ‚<!ENTITY‘ and thus allowing for an xml external entity processing (XXE) attack.
CVE-2019-18412 1 Jetbrains 1 Idetalk 2020-02-06 5.0 MEDIUM 7.5 HIGH
JetBrains IDETalk plugin before version 193.4099.10 allows XXE
CVE-2013-4333 1 Tejimaya 1 Openpne 2020-02-01 6.4 MEDIUM 9.1 CRITICAL
OpenPNE 3 versions 3.8.7, 3.6.11, 3.4.21.1, 3.2.7.6, 3.0.8.5 has an External Entity Injection Vulnerability
CVE-2019-4707 1 Ibm 1 Security Access Manager 2020-01-31 5.5 MEDIUM 7.1 HIGH
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018.
CVE-2017-1000498 1 Androidsvg Project 1 Androidsvg 2020-01-30 6.8 MEDIUM 7.8 HIGH
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
CVE-2014-5238 1 Open-xchange 1 Open-xchange Appsuite 2020-01-28 6.8 MEDIUM 7.8 HIGH
XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document.
CVE-2015-1809 1 Jenkins 1 Cloudbees 2020-01-24 5.0 MEDIUM 7.5 HIGH
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.
CVE-2015-1811 1 Jenkins 1 Cloudbees 2020-01-24 5.0 MEDIUM 7.5 HIGH
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via a crafted XML document.
CVE-2018-10653 1 Citrix 1 Xenmobile Server 2020-01-22 7.5 HIGH 9.8 CRITICAL
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
CVE-2015-8549 1 Pyamf 1 Pyamf 2020-01-22 5.8 MEDIUM 7.1 HIGH
XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or read arbitrary files via a crafted Action Message Format (AMF) payload.
CVE-2020-6958 1 Yet Another Java Service Wrapper Project 1 Yet Another Java Service Wrapper 2020-01-21 6.4 MEDIUM 9.1 CRITICAL
An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.