The Androidsvg Project maintains a specialized SVG rendering library for Android applications, representing a narrowly scoped but potentially widely embedded component in mobile software. The durable signal in its disclosure history centers on improper restriction of XML external entity references, a parsing vulnerability class inherent to SVG processing. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Androidsvg Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000498HIGH AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution | Jan 3, 2018 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Androidsvg Project.
Media articles that mention a CVE ID that affects a product developed by Androidsvg Project — matched by CVE ID, not by vendor name.