Vulnerability Details CVE-2017-12627
In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 80.5%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2017-12627
-
cpe:2.3:a:apache:xerces-c++:-
-
cpe:2.3:a:apache:xerces-c++:1.0.0
-
cpe:2.3:a:apache:xerces-c++:1.0.1
-
cpe:2.3:a:apache:xerces-c++:1.1.0
-
cpe:2.3:a:apache:xerces-c++:1.2.0
-
cpe:2.3:a:apache:xerces-c++:1.3.0
-
cpe:2.3:a:apache:xerces-c++:1.4.0
-
cpe:2.3:a:apache:xerces-c++:1.5.0
-
cpe:2.3:a:apache:xerces-c++:1.5.1
-
cpe:2.3:a:apache:xerces-c++:1.5.2
-
cpe:2.3:a:apache:xerces-c++:1.6.0
-
cpe:2.3:a:apache:xerces-c++:1.7.0
-
cpe:2.3:a:apache:xerces-c++:2.0.0
-
cpe:2.3:a:apache:xerces-c++:2.1.0
-
cpe:2.3:a:apache:xerces-c++:2.2.0
-
cpe:2.3:a:apache:xerces-c++:2.3.0
-
cpe:2.3:a:apache:xerces-c++:2.4.0
-
cpe:2.3:a:apache:xerces-c++:2.5.0
-
cpe:2.3:a:apache:xerces-c++:2.6.0
-
cpe:2.3:a:apache:xerces-c++:2.7.0
-
cpe:2.3:a:apache:xerces-c++:2.8.0
-
cpe:2.3:a:apache:xerces-c++:3.0.0
-
cpe:2.3:a:apache:xerces-c++:3.0.1
-
cpe:2.3:a:apache:xerces-c++:3.1.0
-
cpe:2.3:a:apache:xerces-c++:3.1.1
-
cpe:2.3:a:apache:xerces-c++:3.1.2
-
cpe:2.3:a:apache:xerces-c++:3.1.3
-
cpe:2.3:a:apache:xerces-c++:3.1.4
-
cpe:2.3:a:apache:xerces-c++:3.2.0