← Vulnerability feed

Vulnerability record · CVE-2004-1575 · published 31 December 2004

CVE-2004-1575: Apache xerces-c\+\+ vulnerability

Apache · Xerces C\+\+

The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.

5.0 CVSS 2.0 Medium EPSS 6.2% · top 6.7%
5.0CVSS 2.0 base score
6.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-1575 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-23807Apache xerces-c\+\+ use after free vulnerabilityThe Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users…EPSS 1.5%9.8CVE-2017-12627Apache xerces-c\+\+ null pointer dereference vulnerabilityIn Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain condition…EPSS 8.4%9.8CVE-2016-2099Apache xerces-c\+\+ vulnerabilityUse-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspe…EPSS 6.8%8.8CVE-2023-37536Apache xerces-c\+\+ integer overflow vulnerabilityAn integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.EPSS 1.4%8.1CVE-2018-1311Apache xerces-c\+\+ use after free vulnerabilityThe Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been …EPSS 9.5%7.8CVE-2008-4482Apache xerces-c\+\+ improper input validation vulnerabilityThe XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML sc…EPSS 4.2%7.5CVE-2012-0880Apache xerces-c\+\+ vulnerabilityApache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes has…EPSS 4.4%7.5CVE-2016-4463Apache xerces-c\+\+ memory buffer overflow vulnerabilityStack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2004-1575), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.