CVE-2014-3004 PUBLISHED

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

EPSS 3.63% · 87.7th percentile

Risk Scores

EPSS Score
3.63%
87.7th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTScastor0, 1.3.2-7
Ubuntu:18.04:LTScastor0, 1.3.2-5, 1.3.2-6
Ubuntu:22.04:LTScastor1.3.2-7, 0
Ubuntu:25.10castor0, 1.3.2-7
Ubuntu:24.04:LTScastor0, 1.3.2-7
Ubuntu:16.04:LTScastor0, 1.3.2-3

Timeline

References

Open in Interactive Console →