[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-5265Date: (C)2014-08-19   (M)2023-12-22


The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
DSA-2999
DSA-3001
http://cgit.drupalcode.org/drupal/diff/includes/xmlrpc.inc?id=1849830
https://core.trac.wordpress.org/changeset/29404
https://wordpress.org/news/2014/08/wordpress-3-9-2/
https://www.drupal.org/SA-CORE-2014-004

CPE    122
cpe:/a:wordpress:wordpress:3.0.6
cpe:/a:wordpress:wordpress:3.4.2
cpe:/a:wordpress:wordpress:3.0.5
cpe:/a:wordpress:wordpress:3.4.1
...
CWE    1
CWE-399
OVAL    7
oval:org.secpod.oval:def:107383
oval:org.secpod.oval:def:107345
oval:org.secpod.oval:def:107772
oval:org.secpod.oval:def:107348
...

© SecPod Technologies