Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-2175.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0-rc3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
}
]