Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Angledluffa

#19374of 53,622
13.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-13058
7.5
2022-01-17
Corenlp · Corenlp · CVE-2022-0239
**Name of the Vulnerable Software and Affected Versions** corenlp (affected versions not specified) **Description** The issue is related to Improper Restriction of XML External Entity Reference. No information is provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-13031
6.1
2022-01-13
Corenlp · Corenlp · CVE-2022-0198
**Name of the Vulnerable Software and Affected Versions** corenlp (affected versions not specified) **Description** The issue is related to Improper Restriction of XML External Entity Reference. The `TransformXML()` function uses a `SAXParser` generated from a `SAXParserFactory` with no `FEATURE SECURE PROCESSING` set, allowing for XXE attacks. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.