xerces:xercesImpl@2.12.1 vulnerabilities
-
latest version
2.12.2
-
latest non vulnerable version
-
first published
19 years ago
-
latest version published
2 years ago
-
licenses detected
- [0,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the xerces:xercesImpl package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
xerces:xercesImpl is a that is used for high performance, fully compliant XML parsers in the Apache Xerces family. Affected versions of this package are vulnerable to Denial of Service (DoS) via the XML parser when handling specially crafted XML document payloads. When the parser tries to parse such a document it gets stuck in an infinite loop for a long time, which consumes resources. How to fix Denial of Service (DoS)? Upgrade |
[0,2.12.2)
|