CWE-776
Medium likelihoodImproper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
Parent: CWE-674 - Uncontrolled Recursion
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
86 vulnerabilities with CWE-776
CVE-2024-28982
HIGH
Hitachi Pentaho Business Analytics Server 8.3.0-9.3.0.6 - XML External Entity Injection in ACL Service Endpoint
CVSS 7.1
CVE-2024-27142
MEDIUM
Toshiba Tec e-Studio multi-function peripheral (MFP) - XML External Entity Injection via API Endpoint
CVSS 5.9
CVE-2024-27141
MEDIUM
Toshiba e-Studio MFP API - Blind XML External Entity Injection
CVSS 5.9
CVE-2024-1455
MEDIUM
langchain 0.1.4-0.1.34 - Denial of Service via XML Entity Expansion
CVSS 5.9
CVE-2024-28757
HIGH
libexpat < 2.6.2 - XML Entity Expansion via External Parser
CVSS 7.5
CVE-2023-52426
MEDIUM
libexpat < 2.5.0 - XML Entity Expansion via Recursive Entity References
CVSS 5.5
CVE-2023-49967
HIGH
Typecho 1.2.1 - XML Entity Expansion via XMLRPC Endpoint
CVSS 7.5
CVE-2023-41635
MEDIUM
GruppoSCAI RealGimm <1.1.37p38 - XSS
CVSS 6.5
CVE-2023-3569
MEDIUM
PHOENIX CONTACT TC Router and TC Cloud Client - Authenticated Denial of Service via XML Entity Expansion
CVSS 4.9
CVE-2023-38490
MEDIUM
Kirby <3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, 3.9.6 - XXE
CVSS 6.8
CVE-2023-28118
HIGH
kaml < 0.53.0 - Denial of Service via YAML Anchors and Aliases
CVSS 7.5
CVE-2023-20052
MEDIUM
ClamAV <1.0.0 - Info Disclosure
CVSS 5.3
CVE-2022-28652
MEDIUM
~/.config/apport/settings - Info Disclosure
CVSS 5.5
CVE-2022-44641
MEDIUM
Linaro LAVA < 2022.11 - Authenticated Denial of Service via XML Entity Expansion
CVSS 6.5
CVE-2022-34430
HIGH
Dell Hybrid Client >=1.5 <1.8 - Path Traversal via Zip Bomb in UI
CVSS 7.1
CVE-2022-25857
HIGH
snakeyaml < 1.31 - Denial of Service via Nested Collection Depth
CVSS 7.5
CVE-2022-0217
HIGH
prosody < 0.11.12 - XML External Entity Injection via libexpat Library
CVSS 7.5
CVE-2022-33977
HIGH
untangle < 1.2.0 - Denial of Service via XML Entity Expansion
CVSS 7.5
CVE-2022-34467
MEDIUM
Mendix Excel Importer < 9.2.2 - XML Entity Expansion Injection
CVSS 6.5
CVE-2022-26662
HIGH
Tryton Application Platform <5.0.45-6.2.5 - DoS
CVSS 7.5
CVE-2022-23640
CRITICAL
excel_streaming_reader < 2.1.0 - XML External Entity Injection
CVSS 9.8
CVE-2021-41559
MEDIUM
Silverstripe Framework 4.8.1 - Denial of Service via XML Entity Expansion in Convert::xml2array()
CVSS 6.5
CVE-2021-40511
HIGH
OBDA systems Mastro 1.0 - Denial of Service via XML Entity Expansion
CVSS 7.5
CVE-2021-20464
MEDIUM
IBM Cognos Analytics 11.1.7, 11.2.0 - Authenticated XML Entity Expansion
CVSS 6.5
CVE-2021-31842
MEDIUM
McAfee Endpoint Security < 10.7.0 - Denial of Service via XML Entity Expansion in EPDeploy.xml
CVSS 5.0
Details
Vulnerabilities
86
Exploit Likelihood
Medium