CVE-2023-37536: Apache Xerces-C++
High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
Affected products
- Apache Xerces-C++: version 3.2.3 only
- Fedoraproject Fedora: version 37 only
- Hcltech Bigfix Platform: from 9.0.0, before 9.5.23 (fixed in 9.5.23); from 10.0.0, before 10.0.10 (fixed in 10.0.10)
Published 2023-10-11. Last modified 2026-06-17.