Product:

C3p0

(Mchange)
Repositories https://github.com/zhutougg/c3p0
#Vulnerabilities 2
Date Id Summary Products Score Patch Annotated
2019-04-22 CVE-2019-5427 c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration. Fedora, C3p0, Communications_ip_service_activator, Flexcube_private_banking, Retail_xstore_point_of_service 7.5
2018-12-24 CVE-2018-20433 c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization. Debian_linux, C3p0 9.8