Ghostwire

CVE-2018-25282: Nmap 7.70 contains a denial of service vulnerability that allows local attackers to crash the application by processing...

MEDIUM CVSS 6.2 Exploit Available

Published: April 26, 2026 | Last Modified: April 26, 2026

Description

Nmap 7.70 contains a denial of service vulnerability that allows local attackers to crash the application by processing malicious XML files with exponential entity expansion. Attackers can create a crafted XML file with nested entity definitions and open it through ZenMap's scan import functionality to cause the program to consume excessive system resources and crash.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References