CVE-2012-0881

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
30/10/2017
Last modified:
20/04/2025

Description

Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:xerces2_java:*:*:*:*:*:*:*:* 2.11.0 (including)


References to Advisories, Solutions, and Tools