xmlsec project records
2 published records for vendor xmlsec project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2017-1000061No exploit | xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible informatxmlsec project · xmlsec · CWE-611 | High7.1 | — | 1.3% | Jul 17, 2017 |
23Monitor | CVE-2016-9318No exploit | libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the currexmlsoft · libxml2 · CWE-611 | Medium5.5 | — | 2.9% | Nov 15, 2016 |
- CVE-2017-100006128Monitor
xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible informat
HighCVSS 7.1No exploitEPSS 1%xmlsec project · xmlsecJul 17, 2017
- CVE-2016-931823Monitor
libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the curre
MediumCVSS 5.5No exploitEPSS 3%xmlsoft · libxml2Nov 15, 2016