VendorsApachexerces2_java2.9.1
Vulnerabilities

Apache Software Foundation Xerces2 Java 2.9.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2009-2625
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
Published 2009-08-06 · Modified
5.0EPSS 0.304