Skip to content
Noroxi

xmlsec project records

2 published records for vendor xmlsec project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 16
  2. 17

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

2 records
  • xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible informat

    HighCVSS 7.1No exploitEPSS 1%

    xmlsec project · xmlsecJul 17, 2017

  • CVE-2016-9318
    23Monitor

    libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the curre

    MediumCVSS 5.5No exploitEPSS 3%

    xmlsoft · libxml2Nov 15, 2016