XML Parsing Infinite Loop Affecting xerces:xercesimpl package, versions [,2.3.0)
Threat Intelligence
EPSS
1.56% (88th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-XERCES-30182
- published 6 Jun 2012
- disclosed 6 Jun 2012
- credit Adam Gowdiak, Andrei Costin, Chris Ries, Clayton Smith
Overview
xerces:xercesImpl
XML parsing infinite loop
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, and 6 update 32 and earlier, allows remote attackers to affect availability, related to JAXP.
References
CVSS Scores
version 3.1