Vulnerability

CVE-2012-0881
CVSS Score 7.5 high

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CWE

CWE-399

[CVE-2012-0881] CWE-399

Description

Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.

See xerces/xercesImpl package information