XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
| Software | From | Fixed in |
|---|---|---|
| ibm / java | 5.0.12.2 | 5.0.12.2.x |
| ibm / java | 5.0.12.3 | 5.0.12.3.x |
| ibm / java | 5.0.0.0 | 5.0.0.0.x |
| ibm / java | 5.0.14.0 | 5.0.14.0.x |
| ibm / java | 5.0.11.0 | 5.0.11.0.x |
| ibm / java | 5.0.16.0 | 5.0.16.0.x |
| ibm / java | 5.0.12.1 | 5.0.12.1.x |
| ibm / java | 5.0.13.0 | 5.0.13.0.x |
| ibm / java | 5.0.16.2 | 5.0.16.2.x |
| ibm / java | 5.0.12.4 | 5.0.12.4.x |
| ibm / java | 5.0.11.2 | 5.0.11.2.x |
| ibm / java | 5.0.11.1 | 5.0.11.1.x |
| ibm / java | 5.0.16.1 | 5.0.16.1.x |
| ibm / java | 5.0.12.0 | 5.0.12.0.x |
| ibm / java | 5.0.12.5 | 5.0.12.5.x |
| ibm / java | 5.0.15.0 | 5.0.15.0.x |
| ibm / java | 6.0.3.0 | 6.0.3.0.x |
| ibm / java | 6.0.9.0 | 6.0.9.0.x |
| ibm / java | 6.0.13.0 | 6.0.13.0.x |
| ibm / java | 6.0.10.1 | 6.0.10.1.x |
| ibm / java | 6.0.10.0 | 6.0.10.0.x |
| ibm / java | 6.0.13.2 | 6.0.13.2.x |
| ibm / java | 6.0.6.0 | 6.0.6.0.x |
| ibm / java | 6.0.1.0 | 6.0.1.0.x |
| ibm / java | 6.0.9.1 | 6.0.9.1.x |
| ibm / java | 6.0.12.0 | 6.0.12.0.x |
| ibm / java | 6.0.8.1 | 6.0.8.1.x |
| ibm / java | 6.0.11.0 | 6.0.11.0.x |
| ibm / java | 6.0.5.0 | 6.0.5.0.x |
| ibm / java | 6.0.7.0 | 6.0.7.0.x |
| ibm / java | 6.0.2.0 | 6.0.2.0.x |
| ibm / java | 6.0.13.1 | 6.0.13.1.x |
| ibm / java | 6.0.4.0 | 6.0.4.0.x |
| ibm / java | 6.0.9.2 | 6.0.9.2.x |
| ibm / java | 6.0.8.0 | 6.0.8.0.x |
| ibm / java | 6.0.0.0 | 6.0.0.0.x |
| ibm / java | 7.0.0.0 | 7.0.0.0.x |
| ibm / java | 7.0.2.0 | 7.0.2.0.x |
| ibm / java | 7.0.4.2 | 7.0.4.2.x |
| ibm / java | 7.0.1.0 | 7.0.1.0.x |
| ibm / java | 7.0.4.1 | 7.0.4.1.x |
| ibm / java | 7.0.3.0 | 7.0.3.0.x |
| ibm / java | 7.0.4.0 | 7.0.4.0.x |
| oracle / jre | 1.7.0-update40 | 1.7.0-update40.x |
| oracle / jdk | 1.7.0-update40 | 1.7.0-update40.x |
| oracle / jrockit | r27.7.0 | r27.7.6.x |
| oracle / jrockit | r28.0.0 | r28.2.8.x |
| oracle / jdk | 1.5.0-update51 | 1.5.0-update51.x |
| oracle / jdk | 1.6.0-update60 | 1.6.0-update60.x |
| oracle / jre | 1.5.0-update51 | 1.5.0-update51.x |
| oracle / jre | 1.6.0-update60 | 1.6.0-update60.x |
| ibm / sterling_b2b_integrator | 5.2.4 | 5.2.4.x |
| ibm / host_on-demand | 11.0 | 11.0.x |
| ibm / host_on-demand | 11.0.1 | 11.0.1.x |
| ibm / host_on-demand | 11.0.2 | 11.0.2.x |
| ibm / host_on-demand | 11.0.3 | 11.0.3.x |
| ibm / host_on-demand | 11.0.4 | 11.0.4.x |
| ibm / host_on-demand | 11.0.5 | 11.0.5.x |
| ibm / host_on-demand | 11.0.5.1 | 11.0.5.1.x |
| ibm / host_on-demand | 11.0.6 | 11.0.6.x |
| ibm / host_on-demand | 11.0.6.1 | 11.0.6.1.x |
| ibm / host_on-demand | 11.0.7 | 11.0.7.x |
| ibm / host_on-demand | 11.0.8 | 11.0.8.x |
| ibm / tivoli_application_dependency_discovery_manager | 7.2.2 | 7.2.2.x |
| ibm / sterling_b2b_integrator | 5.1 | 5.1.x |
| ibm / sterling_b2b_integrator | 5.2 | 5.2.x |
| ibm / sterling_file_gateway | 2.1 | 2.1.x |
| ibm / sterling_file_gateway | 2.2 | 2.2.x |
| suse / linux_enterprise_desktop | 11-sp3 | 11-sp3.x |
| suse / linux_enterprise_server | 11-sp3 | 11-sp3.x |
| opensuse / opensuse | 12.3 | 12.3.x |
| suse / linux_enterprise_server | 9 | 9.x |
| opensuse / opensuse | 12.2 | 12.2.x |
| suse / linux_enterprise_server | 11-sp2 | 11-sp2.x |
| suse / linux_enterprise_sdk | 11-sp3 | 11-sp3.x |
| suse / linux_enterprise_server | 10-sp3 | 10-sp3.x |
| suse / linux_enterprise_desktop | 10-sp4 | 10-sp4.x |
| suse / linux_enterprise_server | 10-sp4 | 10-sp4.x |
| suse / linux_enterprise_java | 11-sp2 | 11-sp2.x |
| suse / linux_enterprise_sdk | 11-sp2 | 11-sp2.x |
| suse / linux_enterprise_java | 11-sp3 | 11-sp3.x |
| suse / linux_enterprise_java | 10-sp4 | 10-sp4.x |
| canonical / ubuntu_linux | 13.04 | 13.04.x |
| canonical / ubuntu_linux | 13.10 | 13.10.x |
| canonical / ubuntu_linux | 12.10 | 12.10.x |
| canonical / ubuntu_linux | 10.04 | 10.04.x |
| canonical / ubuntu_linux | 12.04 | 12.04.x |
| apache / xerces2_java | 2.4.0 | 2.12.0 |
xerces / xercesImpl
|
- | 2.12.0 |