VDB
GCVE-110-MAGEIA-2020-51
GCVE-110-MAGEIA-2020-51
Advisory Published
An XML external entity processing vulnerability was found in
extractXmlConfigFromInputStream function in c3p0 (CVE-2018-20433).
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when
loading XML configuration due to missing protections against recursive
entity expansion when loading configuration (CVE-2019-5427).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | rapid-photo-downloader | 0.9.18-1.1.mga7 (unaffected), 0 (affected) | — |
| Mageia | python-colour | 0.1.5-1.mga7 (unaffected), 0 (affected) | — |
| Mageia | python-tenacity | 0 (affected), 5.1.1-1.mga7 (unaffected) | — |
| Mageia | c3p0 | 0 (affected), 0.9.5.4-1.mga7 (unaffected), 0 (affected), 0.9.5.4-1.mga7 (unaffected) | — |
Aliases
Browse GCVE Records
75,726 records in the GCVE database · Updated August 1, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.