CVE-2015-0252 is a denial-of-service vulnerability affecting Apache Xerces-C versions prior to 3.1.2, as well as various Debian and Fedora distributions utilizing this library. An unauthenticated remote attacker can trigger a segmentation fault and crash the application by submitting specially crafted XML data. While the CVSS score is 5.0, indicating a medium severity, its FAUCET Risk Score is 95/100, suggesting a higher practical risk. Although there is no evidence of active exploitation or Metasploit/Nuclei modules, a proof-of-concept exploit is available on ExploitDB, and there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.1:*:*:*:*:*:*:* | ||
20CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:* | ||
21CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:* | ||
22CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* | ||
<= 3.1.1CPE matchmatch criteria | cpe:2.3:a:apache:xerces-c\+\+:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.