Vulnerability Database

289,689

Total vulnerabilities in the database

CVE-2009-2625

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P

No CWE or OWASP classifications available.

Software From Fixed in
oracle / jdk 1.5.0-update11 1.5.0-update11.x
oracle / jdk 1.5.0-update1 1.5.0-update1.x
oracle / jdk 1.5.0-update2 1.5.0-update2.x
oracle / jdk 1.5.0-update3 1.5.0-update3.x
oracle / jdk 1.5.0-update5 1.5.0-update5.x
oracle / jdk 1.5.0-update6 1.5.0-update6.x
oracle / jdk 1.5.0-update7 1.5.0-update7.x
oracle / jdk 1.5.0-update8 1.5.0-update8.x
oracle / jdk 1.5.0-update9 1.5.0-update9.x
oracle / jdk 1.5.0-update10 1.5.0-update10.x
oracle / jdk 1.5.0-update12 1.5.0-update12.x
oracle / jdk 1.5.0-update13 1.5.0-update13.x
oracle / jdk 1.5.0-update14 1.5.0-update14.x
oracle / jdk 1.5.0-update15 1.5.0-update15.x
oracle / jdk 1.5.0-update16 1.5.0-update16.x
oracle / jdk 1.5.0-update17 1.5.0-update17.x
oracle / jdk 1.5.0-update18 1.5.0-update18.x
oracle / jdk 1.5.0-update19 1.5.0-update19.x
oracle / jdk 1.5.0 1.5.0.x
oracle / jdk 1.5.0-update4 1.5.0-update4.x
oracle / jdk 1.6.0 1.6.0.x
oracle / jdk 1.6.0-update10 1.6.0-update10.x
oracle / jdk 1.6.0-update12 1.6.0-update12.x
oracle / jdk 1.6.0-update13 1.6.0-update13.x
oracle / jdk 1.6.0-update14 1.6.0-update14.x
oracle / jdk 1.6.0-update11 1.6.0-update11.x
oracle / jdk 1.6.0-update1 1.6.0-update1.x
oracle / jdk 1.6.0-update2 1.6.0-update2.x
oracle / jdk 1.6.0-update3 1.6.0-update3.x
oracle / jdk 1.6.0-update4 1.6.0-update4.x
oracle / jdk 1.6.0-update5 1.6.0-update5.x
oracle / jdk 1.6.0-update7 1.6.0-update7.x
oracle / jdk 1.6.0-update6 1.6.0-update6.x
fedoraproject / fedora 11 11.x
fedoraproject / fedora 10 10.x
opensuse / opensuse 11.1 11.1.x
suse / linux_enterprise_server 9 9.x
opensuse / opensuse 11.0 11.0.x
opensuse / opensuse 11.2 11.2.x
suse / linux_enterprise_server 10-sp2 10-sp2.x
suse / linux_enterprise_server 11 11.x
suse / linux_enterprise_server 10-sp3 10-sp3.x
debian / debian_linux 5.0 5.0.x
debian / debian_linux 4.0 4.0.x
canonical / ubuntu_linux 9.04 9.04.x
canonical / ubuntu_linux 8.10 8.10.x
canonical / ubuntu_linux 9.10 9.10.x
canonical / ubuntu_linux 8.04 8.04.x
canonical / ubuntu_linux 6.06 6.06.x
oracle / primavera_web_services 7.0 7.0.x
oracle / primavera_web_services 7.0-sp1 7.0-sp1.x
oracle / primavera_web_services 6.2.1 6.2.1.x
oracle / primavera_p6_enterprise_project_portfolio_management 6.2.1 6.2.1.x
oracle / primavera_p6_enterprise_project_portfolio_management 7.0 7.0.x
oracle / primavera_p6_enterprise_project_portfolio_management 6.1 6.1.x
apache / xerces2_java 2.9.1 2.9.1.x
xerces / xercesImpl - 2.10.0