5
CVSSv2

CVE-2015-0252

Published: 24/03/2015 Updated: 05/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

internal/XMLReader.cpp in Apache Xerces-C prior to 3.1.2 allows remote malicious users to cause a denial of service (segmentation fault and crash) via crafted XML data.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 7.1

fedoraproject fedora 22

fedoraproject fedora 20

fedoraproject fedora 21

apache xerces-c\\+\\+

Vendor Advisories

Debian Bug report logs - #780827 xerces-c: CVE-2015-0252: Apache Xerces-C XML Parser Crashes on Malformed Input Package: src:xerces-c; Maintainer for src:xerces-c is William Blough <bblough@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 20 Mar 2015 05:54:01 UTC Severity: grave Tags: fix ...
Debian Bug report logs - #780827 xerces-c: CVE-2015-0252: Apache Xerces-C XML Parser Crashes on Malformed Input Package: src:xerces-c; Maintainer for src:xerces-c is William Blough <bblough@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 20 Mar 2015 05:54:01 UTC Severity: grave Tags: fix ...
A flaw was found in the way the Xerces-C XML parser processed certain XML documents A remote attacker could provide specially crafted XML input that, when parsed by an application using Xerces-C, would cause that application to crash ...

Exploits

# Exploit Title: Apache Xerces-C XML Parser (< 312) DoS POC # Date: 2015-05-03 # Exploit Author: beford # Vendor Homepage: xercesapacheorg/#xerces-c # Version: Versions prior to 312 # Tested on: Ubuntu 1504 # CVE : CVE-2015-0252 Apache Xerces-C XML Parser Crashes on Malformed Input I believe this to be the same issue that was rep ...
Apache Xerces-C XML Parser versions prior to 312 denial of service proof of concept exploit ...