Xerces C

Vendor:

First CVE: Dec 31, 2004 · Active for 21 years

11
Total CVEs
More Total CVEs than 89% of tracked products
1.1
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Xerces C over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Feb 29, 2024
876 days ago

CVE Severity & Scoring

Xerces C11 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (63.6%)
Unknown4 (36.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (54.5%)
High1 (9.1%)
Unknown4 (36.4%)
User Interaction
None7 (63.6%)
Unknown4 (36.4%)
Required0 (0.0%)
Privileges Required
Low1 (9.1%)
High0 (0.0%)
None6 (54.5%)
Unknown4 (36.4%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.
Mar 24, 20155.050NOYES
Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid ch
May 13, 20169.834NONO
In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.
Mar 1, 20189.833NONO
Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.
Jul 8, 20167.532NONO
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained ver
Dec 18, 20198.131NONO
The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to
Feb 29, 20249.827NONO
Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes hash table collisions.
Aug 8, 20177.526NONO
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
Oct 11, 20238.824NONO
The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML schema definition with a large ma
Oct 8, 20087.821NONO
Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application c
Aug 11, 20094.319NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Xerces C

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.2.318.81.4%00
2.8.014.35.3%00
2.7.026.04.8%00
2.6.017.84.2%00
2.5.026.45.2%00
2.4.017.84.2%00
2.3.017.84.2%00
2.2.017.84.2%00
2.1.017.84.2%00
2.0.017.84.2%00
1.7.017.84.2%00
1.6.017.84.2%00
1.5.017.84.2%00
1.4.017.84.2%00
1.3.017.84.2%00
1.2.017.84.2%00
1.1.017.84.2%00
1.0.117.84.2%00
1.0.017.84.2%00