← Vulnerability feed

Vulnerability record · CVE-2017-12627 · published 1 March 2018

CVE-2017-12627: Apache xerces-c\+\+ null pointer dereference vulnerability

Apache · Xerces C\+\+

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.

9.8 CVSS 3.0 Critical EPSS 8.4% · top 5.2% CWE-476 · NULL pointer dereference
9.8CVSS 3.0 base score, v2 7.5
8.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12627 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-23807Apache xerces-c\+\+ use after free vulnerabilityThe Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users…EPSS 1.5%9.8CVE-2016-2099Apache xerces-c\+\+ vulnerabilityUse-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspe…EPSS 6.8%8.8CVE-2023-37536Apache xerces-c\+\+ integer overflow vulnerabilityAn integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.EPSS 1.4%8.1CVE-2018-1311Apache xerces-c\+\+ use after free vulnerabilityThe Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been …EPSS 9.5%7.8CVE-2008-4482Apache xerces-c\+\+ improper input validation vulnerabilityThe XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML sc…EPSS 4.2%7.5CVE-2012-0880Apache xerces-c\+\+ vulnerabilityApache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes has…EPSS 4.4%7.5CVE-2016-4463Apache xerces-c\+\+ memory buffer overflow vulnerabilityStack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.EPSS 14%5.0CVE-2015-0252Debian linux improper input validation vulnerabilityinternal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafte…EPSS 40%

Source: NIST National Vulnerability Database (record CVE-2017-12627), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.