CVE Tools

Xerces-c\+\+

11 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Xerces-c\+\+, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Xerces-c\+\+ CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Xerces-c\+\+ CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 11 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical327%
  • High545%
  • Medium327%

Latest CVEs

The 11 most recently published vulnerabilities affecting Xerces-c\+\+.

  1. CVE-2024-23807Apache Xerces C++: Use-after-free on external DTD scan9.8
  2. CVE-2023-37536HCL BigFix Platform is vulnerable to an integer overflow in xerces-c++ 3.2.38.2
  3. CVE-2018-1311The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the libra...8.1
  4. CVE-2017-12627In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.9.8
  5. CVE-2012-0880Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes hash table collisions.7.5
  6. CVE-2016-4463Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.7.5
  7. CVE-2016-2099Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid character in an XML...9.8
  8. CVE-2015-0252internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.5.0
  9. CVE-2009-1885Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors...4.3
  10. CVE-2008-4482The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML schema definition with a large maxOccurs value, wh...7.8
  11. CVE-2004-1575The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.5.0

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store