
CVE-2019-9628 – Ubuntu Security Notice USN-3921-1
https://notcve.org/view.php?id=CVE-2019-9628
12 Mar 2019 — The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type. La libreria XMLTooling, en todas las versiones anteriores a la V3.0.4, suministrada con el software OpenSAML y Shibboleth Service Provider, contiene una clase de parser XML. Los datos no válidos en ... • http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00079.html • CWE-755: Improper Handling of Exceptional Conditions •

CVE-2015-0851 – Debian Security Advisory 3321-1
https://notcve.org/view.php?id=CVE-2015-0851
03 Aug 2015 — XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data. Vulnerabilidad en XMLTooling-C en versión anterior a 1.5.5, tal como se utiliza en OpenSAML-C y Shibboleth Service Provider (SP), no maneja correctamente las excepciones de conversión de entero, lo que permite a atacantes remotos provocar una denegación de servicio (caída)... • http://shibboleth.net/community/advisories/secadv_20150721.txt • CWE-189: Numeric Errors •