CVE-2017-12627: Apache Xerces-C++
Critical severity, CVSS 9.8. EPSS: 8.1% chance of exploitation in the next 30 days.
In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.
Affected products
- Apache Xerces-C++: before 3.2.1 (fixed in 3.2.1)
Published 2018-03-01. Last modified 2026-06-17.