CVE-2017-12627 PUBLISHED

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.

EPSS 5.32% · 90.0th percentile

Risk Scores

EPSS Score
5.32%
90.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSxerces-c0, 3.1.1-5.1, 3.1.2+debian-1
Ubuntu:Pro:18.04:LTSxerces-c0, 3.1.4+debian-2, 3.1.4+debian-2build1
Ubuntu:14.04:LTSxerces-c0, 3.1.1-5.1+deb8u3build0.14.04.1, 3.1.1-3

Timeline

References

Open in Interactive Console →