cbcvebase.

Apache Xml Security For C vulnerabilities

6 known vulnerabilities affecting apache/xml_security_for_c.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2013-2156P3HIGHCVSS 7.5≤ 1.7.0v0.1.0+11 more2013-08-20
CVE-2013-2156 [HIGH] CWE-119 CVE-2013-2156: Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010 Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010315.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PrefixList attribute.
nvd
CVE-2013-2154P3HIGHCVSS 7.5≤ 1.7.0v0.1.0+11 more2013-08-20
CVE-2013-2154 [HIGH] CWE-119 CVE-2013-2154: Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cp Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions, probably related to the DSIGRefer
nvd
CVE-2013-2210P3HIGHCVSS 7.5≤ 1.7.1v0.1.0+12 more2013-08-20
CVE-2013-2210 [HIGH] CVE-2013-2210: Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Secu Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions. NOTE: this is due to an incorrect fix for CVE-2013-2154.
nvd
CVE-2013-2155P4MEDIUMCVSS 5.8≤ 1.7.0v0.1.0+11 more2013-08-20
CVE-2013-2155 [MEDIUM] CVE-2013-2155: Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate l Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted length values to the (1) compareBase64StringToRaw, (2) DSIGAlgorithmHandlerDefault, or (3) DSIGAlgorithmH
nvd
CVE-2011-2516P4MEDIUMCVSS 5.0v1.6.02011-07-11
CVE-2011-2516 [MEDIUM] CWE-189 CVE-2011-2516: Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibb Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
nvd
CVE-2013-2153P4MEDIUMCVSS 4.3≤ 1.7.0v0.1.0+11 more2013-08-20
CVE-2013-2153 [MEDIUM] CWE-310 CVE-2013-2153: The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Securi The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to reuse signatures and spoof arbitrary content via crafted Reference elements in the Signature, aka "XML Signature Bypass issue."
nvd
Apache Xml Security For C vulnerabilities | cvebase