VDB
GCVE-VVD-MAGEIA-2018-178
GCVE-VVD-MAGEIA-2018-178
Advisory Published
The Xerces-C XML parser mishandles certain kinds of external DTD
references, resulting in dereference of a NULL pointer while processing
the path to the DTD. The bug allows for a denial of service attack in
applications that allow DTD processing and do not prevent external DTD
usage, and could conceivably result in remote code execution
(CVE-2017-12627).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | kmod-virtualbox | 0 (affected), 5.2.22-2.mga6 (unaffected) | — |
| Mageia | virtualbox | 0 (affected), 5.2.22-1.1.mga6 (unaffected) | — |
| Mageia | kmod-vboxadditions | 0 (affected), 5.2.22-2.mga6 (unaffected) | — |
| Mageia | xerces-c | 0 (affected), 3.1.2-1.4.mga5 (unaffected), 0 (affected), 3.1.2-1.4.mga5 (unaffected) | — |
Aliases
Transitive aliases
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.