Skip to main content

CWE archive

CWE-611 CVEs

Programmatic archive

1,270 CVEs tagged with CWE-611259 Critical, 567 High, 410 Medium, 34 Low, 0 Unrated.

CVE-2017-5992

Published Feb 15, 2017

Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8348

Published Feb 13, 2017

An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakl…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-3027

Published Feb 1, 2017

IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could…

CVSS 6.5 · Medium

CVE-2016-2908

Published Feb 1, 2017

IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parse…

CVSS 9.1 · Critical

CVE-2015-7743

Published Jan 23, 2017

XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10097

Published Jan 2, 2017

XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLReques…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7460

Published Dec 29, 2016

The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or c…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-7459

Published Dec 29, 2016

VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Conte…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-7458

Published Dec 29, 2016

VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity d…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-9181

Published Dec 22, 2016

perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9180

Published Dec 22, 2016

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardl…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4047

Published Dec 15, 2016

An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev8. References to external Open XML document type definitions (.dtd resources) can be placed within .docx and .…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3055

Published Dec 1, 2016

IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document c…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3033

Published Dec 1, 2016

IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0284

Published Nov 24, 2016

The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Qual…

CVSS 5.4 · Medium

CVE-2016-9563

Published Nov 23, 2016

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwl…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
50.6
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2015-1832

Published Oct 3, 2016

XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers t…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-6408

Published Sep 24, 2016

Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, relat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4264

Published Sep 1, 2016

The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files or send TCP requests to intrane…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1,226-1,250 of 1,270 CVEsPage 50 of 51