CVE-2012-0881
published 2017-10-30CVE-2012-0881: Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which…
PriorityP345high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
17.46%
96.8th percentile
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | xerces2_java | <= 2.11.0 | — |
| debian | libxerces2-java | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5LOW
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Denial of service in Apache Xerces2
osv·2020-06-15
CVE-2012-0881 [HIGH] Denial of service in Apache Xerces2
Denial of service in Apache Xerces2
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
GHSA
Denial of service in Apache Xerces2
ghsa·2020-06-15
CVE-2012-0881 [HIGH] CWE-400 Denial of service in Apache Xerces2
Denial of service in Apache Xerces2
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
OSV
CVE-2012-0881: Apache Xerces2 Java Parser before 2
osv·2017-10-30·CVSS 7.5
CVE-2012-0881 [HIGH] CVE-2012-0881: Apache Xerces2 Java Parser before 2
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
Oracle
Oracle Oracle Supply Chain Risk Matrix: UI Infrastructure (Apache Xerces2 Java Parser) — CVE-2012-0881
vendor_oracle·2021-07-15·CVSS 7.5
CVE-2012-0881 [HIGH] Oracle Oracle Supply Chain Risk Matrix: UI Infrastructure (Apache Xerces2 Java Parser) — CVE-2012-0881
Oracle Oracle Supply Chain Risk Matrix: UI Infrastructure (Apache Xerces2 Java Parser) vulnerability
CVE: CVE-2012-0881
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Red Hat
xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)
vendor_redhat·2014-07-08·CVSS 7.5
CVE-2012-0881 [HIGH] CWE-407 xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)
xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
Statement: This issue affects the versions of xerces as shipped with Red Hat Enterprise Linux 6. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: xerces-j2 (Red Hat Enterprise Linux 5) - Affected
Package: xerces-j2 (Red Hat Enterprise Linux 6) - Affected
Package: xerces-j2 (Red Hat JBoss Enterprise Web Server 1) - Affect
Debian
CVE-2012-0881: libxerces2-java - Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a deni...
vendor_debian·2012·CVSS 7.5
CVE-2012-0881 [HIGH] CVE-2012-0881: libxerces2-java - Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a deni...
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4966 freeradius: does not respect expired passwords when using the unix module
bugzilla·2012-11-21·CVSS 6.0
CVE-2011-4966 [MEDIUM] CVE-2011-4966 freeradius: does not respect expired passwords when using the unix module
CVE-2011-4966 freeradius: does not respect expired passwords when using the unix module
When FreeRADIUS is configured to use the 'unix' module and shadow passwords, the password expiration field is ignored. This could allow a user with an expired password to authenticate against FreeRADIUS.
This was corrected upstream:
https://github.com/alandekok/freeradius-server/commit/1b1ec5ce75e224bd1755650c18ccdaa6dc53e605
And was also corrected in Red Hat Enterprise Linux 6 via RHBA-2012:0881:
https://rhn.redhat.com/errata/RHBA-2012-0881.html
Statement:
(none)
Discussion:
This issue affects the version of freeradius and freeradius2 as shipped with Red Hat Enterprise Linux 5.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0134 https://rh
Bugzilla
CVE-2012-0881 xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)
bugzilla·2012-02-03·CVSS 7.5
CVE-2012-0881 [HIGH] CVE-2012-0881 xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)
CVE-2012-0881 xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)
Juraj Somorovsky reported that certain XML parsers/servers are affected by the
same, or similar, flaw as the hash table collisions CPU usage denial of
service. Sending a specially crafted message to an XML service can result in
longer processing time, which could lead to a denial of service. It is
reported that this attack on XML can be applied on different XML nodes (such as
entities, element attributes, namespaces, various elements in the XML security,
etc.).
xerces-j2 is written in Java and makes significant use of arrays.
Discussion:
Statement:
This issue affects the versions of xerces as shipped with Red Hat Enterprise Linux 6. Red Hat Product Security has rated this issue as having Moderate securit
arXiv
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
arxiv_fulltext·2024-09-04
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
Fangyuan Zhang,
Lingling Fan*,
Sen Chen,
Miaoying Cai,
Sihan Xu,
and Lida Zhao
Fangyuan Zhang and Miaoying Cai are with DISSec, NDST, College of Computer Science, Nankai University, China. Emails: \fangyuanzhang, miaoyingcai\@mail.nankai.edu.cn.
Lingling Fan (Corresponding author) and Sihan Xu are with DISSec, NDST, College of Cyber Science, Nankai University, China. Emails: \linglingfan, xusihan\@nankai.edu.cn.
Sen Chen is with the College of Intelligence and Computing, Tianjin University, China. Email: [email protected].
Lida Zhao is with School of Computer Science and Engineering, Nanyang Technological University. Email: [email protected].
Journal of \ Class Files, Vol. XX,
http://www.openwall.com/lists/oss-security/2014/07/08/11https://bugzilla.redhat.com/show_bug.cgi?id=787104https://issues.apache.org/jira/browse/XERCESJ-1685https://lists.apache.org/thread.html/49dc6702104a86ecbb40292dcd329ce9ae4c32b74733199ecab14a73%40%3Cj-users.xerces.apache.org%3Ehttps://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3Ehttps://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://lists.apache.org/thread.html/rea7b831dceeb2a2fa817be6f63b08722042e3647fb2d47c144370a56%40%3Ccommon-issues.hadoop.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.htmlhttp://www.openwall.com/lists/oss-security/2014/07/08/11https://bugzilla.redhat.com/show_bug.cgi?id=787104https://issues.apache.org/jira/browse/XERCESJ-1685https://lists.apache.org/thread.html/49dc6702104a86ecbb40292dcd329ce9ae4c32b74733199ecab14a73%40%3Cj-users.xerces.apache.org%3Ehttps://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3Ehttps://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://lists.apache.org/thread.html/rea7b831dceeb2a2fa817be6f63b08722042e3647fb2d47c144370a56%40%3Ccommon-issues.hadoop.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.html
2017-10-30
Published