Skip to content

Commit 3cba542

Browse files
matteogreekcopernico
authored andcommitted
Add 133 new statements, strict subset of Prospector's findings
1 parent b378206 commit 3cba542

File tree

133 files changed

+5883
-0
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

133 files changed

+5883
-0
lines changed
Lines changed: 92 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,92 @@
1+
vulnerability_id: CVE-2009-2625
2+
notes:
3+
- links:
4+
- https://issues.apache.org/jira/browse/XERCESJ-1412.
5+
text: XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
6+
fixes:
7+
- id: DEFAULT_BRANCH
8+
commits:
9+
- id: "787352"
10+
repository: http://svn.apache.org/repos/asf/xerces/java
11+
artifacts:
12+
- id: pkg:maven/xerces/xercesImpl@2.11.0
13+
reason: Reviewed manually
14+
affected: false
15+
- id: pkg:maven/xerces/xercesImpl@2.8.1
16+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
17+
affected: true
18+
- id: pkg:maven/xerces/xercesImpl@2.4.0
19+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
20+
affected: true
21+
- id: pkg:maven/xerces/xercesImpl@2.0.2
22+
reason: Reviewed manually
23+
affected: true
24+
- id: pkg:maven/xerces/xercesImpl@2.0.2
25+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
26+
affected: true
27+
- id: pkg:maven/xerces/xercesImpl@2.9.0
28+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
29+
affected: true
30+
- id: pkg:maven/xerces/xercesImpl@2.9.0
31+
reason: Reviewed manually
32+
affected: true
33+
- id: pkg:maven/xerces/xercesImpl@2.6.2
34+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
35+
affected: true
36+
- id: pkg:maven/xerces/xercesImpl@2.8.0
37+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
38+
affected: true
39+
- id: pkg:maven/xerces/xercesImpl@2.3.0
40+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
41+
affected: true
42+
- id: pkg:maven/xerces/xercesImpl@2.3.0
43+
reason: Reviewed manually
44+
affected: true
45+
- id: pkg:maven/xerces/xercesImpl@2.7.1
46+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
47+
affected: true
48+
- id: pkg:maven/xerces/xercesImpl@2.7.1
49+
reason: Reviewed manually
50+
affected: true
51+
- id: pkg:maven/xerces/xercesImpl@2.2.1
52+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
53+
affected: true
54+
- id: pkg:maven/xerces/xercesImpl@2.2.1
55+
reason: Reviewed manually
56+
affected: true
57+
- id: pkg:maven/org.apache.servicemix.bundles/org.apache.servicemix.bundles.xerces@2.9.1_5
58+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
59+
affected: true
60+
- id: pkg:maven/org.apache.servicemix.bundles/org.apache.servicemix.bundles.xerces@2.9.1_5
61+
reason: Reviewed manually
62+
affected: true
63+
- id: pkg:maven/xerces/xercesImpl@2.11.0
64+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
65+
affected: false
66+
- id: pkg:maven/xerces/xercesImpl@2.10.0
67+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
68+
affected: false
69+
- id: pkg:maven/xerces/xercesImpl@2.9.1
70+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
71+
affected: true
72+
- id: pkg:maven/xerces/xercesImpl@2.9.1
73+
reason: Reviewed manually
74+
affected: true
75+
- id: pkg:maven/xerces/xercesImpl@2.6.1
76+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
77+
affected: true
78+
- id: pkg:maven/xerces/xercesImpl@2.12.0
79+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
80+
affected: false
81+
- id: pkg:maven/org.apache.servicemix.bundles/org.apache.servicemix.bundles.xerces@2.12.0_1
82+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
83+
affected: false
84+
- id: pkg:maven/com.rackspace.apache/xerces2-xsd11@2.11.1
85+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
86+
affected: false
87+
- id: pkg:maven/org.apache.avro/avro-tools@1.9.1
88+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
89+
affected: true
90+
- id: pkg:maven/org.apache.avro/avro-tools@1.9.2
91+
reason: Assessed with Eclipse Steady (AST_EQUALITY)
92+
affected: true

0 commit comments

Comments
 (0)