MarkLogic is a NoSQL database platform deployed in enterprises for document management and search workloads, where a meaningful share of its vulnerabilities reach critical severity. The recurring exposure centers on memory-safety issues, particularly improper bounds checking in buffer operations, reflecting the complexity inherent in a native-code database engine handling unstructured data at scale. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Marklogic over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-2792CRITICAL An exploitable heap corruption vulnerability exists in the iBldDirInfo functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause | Sep 7, 2018 | 9.6 | 30 | NO | NO |
CVE-2016-8384HIGH An exploitable heap corruption vulnerability exists in the DHFSummary functionality of AntennaHouse DMC HTMLFilter. | Apr 24, 2018 | 8.8 | 25 | NO | NO |
CVE-2016-8383HIGH An exploitable heap corruption vulnerability exists in the Doc_GetFontTable functionality of AntennaHouse DMC HTMLFilter. A specially crafted doc file can cause a heap corruption r | Apr 24, 2018 | 8.8 | 24 | NO | NO |
CVE-2016-8382HIGH An exploitable heap corruption vulnerability exists in the Doc_SetSummary functionality of AntennaHouse DMC HTMLFilter. A specially crafted doc file can cause a heap corruption res | Apr 24, 2018 | 8.8 | 24 | NO | NO |
CVE-2017-2795HIGH An exploitable heap corruption vulnerability exists in the Txo functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted xls file can cause a he | Sep 7, 2018 | 8.6 | 21 | NO | NO |
CVE-2017-2799HIGH An exploitable heap corruption vulnerability exists in the AddSst functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a | May 24, 2017 | 7.8 | 20 | NO | NO |
CVE-2017-2798HIGH An exploitable heap corruption vulnerability exists in the GetIndexArray functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can | May 24, 2017 | 7.8 | 20 | NO | NO |
CVE-2017-2797HIGH An exploitable heap overflow vulnerability exists in the ParseEnvironment functionality of AntennaHouse DMC HTMLFilter as used by MarkLogic 8.0-6. | May 23, 2017 | 7.8 | 20 | NO | NO |
CVE-2017-2794HIGH An exploitable stack-based buffer overflow vulnerability exists in the DHFSummary functionality of AntennaHouse DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted PPT f | May 23, 2017 | 7.8 | 20 | NO | NO |
CVE-2017-2793HIGH An exploitable heap corruption vulnerability exists in the UnCompressUnicode functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can | May 23, 2017 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Marklogic.
Media articles that mention a CVE ID that affects a product developed by Marklogic — matched by CVE ID, not by vendor name.