CVE Security Report Legacy - SICS Naming Service

CVE Security Report Legacy - SICS Naming Service

The report contains data retrieved from the National Vulnerability Database: https://nvd.nist.gov, NPM Public Advisories: https://www.npmjs.com/advisories, and the RetireJS community.

Name Description CWE CVSS v2.0 Severity CVSS v3.0 Severity Dependency Products
CVE-2024-7254 Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker. CWE-400 HIGH protobuf-java-3.25.1.jar
CVE-2016-4570 The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. CWE-400 HIGH MEDIUM webservices-extra-api-2.4.10.jar (shaded: jakarta.xml.registry:jakarta.xml.registry-api:1.0.10)
CVE-2016-4571 The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. CWE-400 HIGH MEDIUM webservices-extra-api-2.4.10.jar (shaded: jakarta.xml.registry:jakarta.xml.registry-api:1.0.10)
CVE-2016-4570 The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. CWE-400 HIGH MEDIUM webservices-extra-api-2.4.10.jar (shaded: jakarta.xml.rpc:jakarta.xml.rpc-api:1.1.4)
CVE-2016-4571 The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. CWE-400 HIGH MEDIUM webservices-extra-api-2.4.10.jar (shaded: jakarta.xml.rpc:jakarta.xml.rpc-api:1.1.4)

This report was generated 09.09.2025, 16:47:12 UTC, using dependency-check version: 12.1.1.