Xerces C
Vendor:
First CVE: Dec 31, 2004 · Active for 21 years
11
Total CVEs
More Total CVEs than 89% of tracked products
1.1
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Xerces C over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Feb 29, 2024
876 days ago
CVE Severity & Scoring
Xerces C11 CVEs
27%
45%
27%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (63.6%)
Unknown4 (36.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (54.5%)
High1 (9.1%)
Unknown4 (36.4%)
User Interaction
None7 (63.6%)
Unknown4 (36.4%)
Required0 (0.0%)
Privileges Required
Low1 (9.1%)
High0 (0.0%)
None6 (54.5%)
Unknown4 (36.4%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-0252MEDIUM internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data. | Mar 24, 2015 | 5.0 | 50 | NO | YES |
CVE-2016-2099CRITICAL Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid ch | May 13, 2016 | 9.8 | 34 | NO | NO |
CVE-2017-12627CRITICAL In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions. | Mar 1, 2018 | 9.8 | 33 | NO | NO |
CVE-2016-4463HIGH Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD. | Jul 8, 2016 | 7.5 | 32 | NO | NO |
CVE-2018-1311HIGH The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained ver | Dec 18, 2019 | 8.1 | 31 | NO | NO |
CVE-2024-23807CRITICAL The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs.
Users are recommended to upgrade to | Feb 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2012-0880HIGH Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes hash table collisions. | Aug 8, 2017 | 7.5 | 26 | NO | NO |
CVE-2023-37536HIGH An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. | Oct 11, 2023 | 8.8 | 24 | NO | NO |
CVE-2008-4482HIGH The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML schema definition with a large ma | Oct 8, 2008 | 7.8 | 21 | NO | NO |
CVE-2009-1885MEDIUM Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application c | Aug 11, 2009 | 4.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Xerces C
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2.3 | 1 | 8.8 | 1.4% | 0 | 0 |
| 2.8.0 | 1 | 4.3 | 5.3% | 0 | 0 |
| 2.7.0 | 2 | 6.0 | 4.8% | 0 | 0 |
| 2.6.0 | 1 | 7.8 | 4.2% | 0 | 0 |
| 2.5.0 | 2 | 6.4 | 5.2% | 0 | 0 |
| 2.4.0 | 1 | 7.8 | 4.2% | 0 | 0 |
| 2.3.0 | 1 | 7.8 | 4.2% | 0 | 0 |
| 2.2.0 | 1 | 7.8 | 4.2% | 0 | 0 |
| 2.1.0 | 1 | 7.8 | 4.2% | 0 | 0 |
| 2.0.0 | 1 | 7.8 | 4.2% | 0 | 0 |
| 1.7.0 | 1 | 7.8 | 4.2% | 0 | 0 |
| 1.6.0 | 1 | 7.8 | 4.2% | 0 | 0 |
| 1.5.0 | 1 | 7.8 | 4.2% | 0 | 0 |
| 1.4.0 | 1 | 7.8 | 4.2% | 0 | 0 |
| 1.3.0 | 1 | 7.8 | 4.2% | 0 | 0 |
| 1.2.0 | 1 | 7.8 | 4.2% | 0 | 0 |
| 1.1.0 | 1 | 7.8 | 4.2% | 0 | 0 |
| 1.0.1 | 1 | 7.8 | 4.2% | 0 | 0 |
| 1.0.0 | 1 | 7.8 | 4.2% | 0 | 0 |