Apache / Log4net
3 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-40021 | Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters | MEDIUM | 6.3 | Apr 10, 2026 |
| CVE-2018-1285 | Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in appli… | CRITICAL | 9.8 | May 11, 2020 |
| CVE-2006-0743 | Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and ter… | MEDIUM | 5.0 | Mar 9, 2006 |
Showing 1 to 3 of 3 CVEs