ZeroHour

CVE-2019-12154

CVSS 3.0
9.1 critical
EPSS
2%p80
Published
()
Modified
Description

XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced resources, leading to disclosure of local file contents and/or denial of service conditions.

Vendors
realobjects
Products
pdfreactor
Weakness
CWE-611
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.