Xoev's vulnerability footprint centers on the OSCI Transport Library, a specialized component supporting secure data exchange in German e-government infrastructure. Its observed weaknesses cluster around XML parsing, cryptographic validation, and algorithm strength, reflecting the authentication and encryption demands of trusted document transmission in that domain. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xoev over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-10670CRITICAL An XML External Entity (XXE) issue exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET), exploitable by sending a craft | Jun 30, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-10668MEDIUM A Padding Oracle exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). Under an MITM condition within the OSCI infrastr | Jun 30, 2017 | 5.9 | 20 | NO | NO |
CVE-2017-10669MEDIUM Signature Wrapping exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). An attacker with access to unencrypted OSCI pr | Jun 30, 2017 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xoev.
Media articles that mention a CVE ID that affects a product developed by Xoev — matched by CVE ID, not by vendor name.