Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Angledluffa

#20092of 55,077
13.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-13058
7.5
2022-01-17
Corenlp · Corenlp · CVE-2022-0239
**Name of the Vulnerable Software and Affected Versions** corenlp (affected versions not specified) **Description** The issue is related to Improper Restriction of XML External Entity Reference. No information is provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-13031
6.1
2022-01-13
Corenlp · Corenlp · CVE-2022-0198
**Name of the Vulnerable Software and Affected Versions** corenlp (affected versions not specified) **Description** The issue is related to Improper Restriction of XML External Entity Reference. The `TransformXML()` function uses a `SAXParser` generated from a `SAXParserFactory` with no `FEATURE SECURE PROCESSING` set, allowing for XXE attacks. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.