Search Results (Refine Search)
- Results Type: Overview
- Search Type: Search All
- CPE Vendor: cpe:/:mchange
- CPE Product: cpe:/:mchange:c3p0
- CPE Product Version: cpe:/:mchange:c3p0:0.9.5
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2019-5427 |
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration. Published: April 22, 2019; 5:29:00 PM -0400 |
V4.0:(not available) V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |