Количество 6
Количество 6
CVE-2019-5427
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
CVE-2019-5427
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
CVE-2019-5427
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
CVE-2019-5427
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack whe ...
GHSA-84p2-vf58-xhxv
Billion laughs attack in c3p0
BDU:2020-01665
Уязвимость функции ConfigXmlUtils библиотеки работы с JDBC-драйверами c3p0, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-5427 c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration. | CVSS3: 7.5 | 4% Низкий | почти 7 лет назад | |
CVE-2019-5427 c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration. | CVSS3: 4.4 | 4% Низкий | почти 7 лет назад | |
CVE-2019-5427 c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration. | CVSS3: 7.5 | 4% Низкий | почти 7 лет назад | |
CVE-2019-5427 c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack whe ... | CVSS3: 7.5 | 4% Низкий | почти 7 лет назад | |
GHSA-84p2-vf58-xhxv Billion laughs attack in c3p0 | CVSS3: 7.5 | 4% Низкий | почти 7 лет назад | |
BDU:2020-01665 Уязвимость функции ConfigXmlUtils библиотеки работы с JDBC-драйверами c3p0, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 4% Низкий | почти 7 лет назад |
Уязвимостей на страницу