[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253562

 
 

909

 
 

197267

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-5266Date: (C)2014-08-19   (M)2023-12-22


The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
DSA-2999
DSA-3001
http://cgit.drupalcode.org/drupal/diff/includes/xmlrpc.inc?id=1849830
http://cgit.drupalcode.org/drupal/diff/modules/openid/xrds.inc?id=1849830
https://core.trac.wordpress.org/changeset/29404
https://wordpress.org/news/2014/08/wordpress-3-9-2/
https://www.drupal.org/SA-CORE-2014-004

CPE    122
cpe:/a:wordpress:wordpress:3.0.6
cpe:/a:wordpress:wordpress:3.4.2
cpe:/a:wordpress:wordpress:3.0.5
cpe:/a:wordpress:wordpress:3.4.1
...
CWE    1
CWE-399
OVAL    7
oval:org.secpod.oval:def:107383
oval:org.secpod.oval:def:107345
oval:org.secpod.oval:def:107772
oval:org.secpod.oval:def:107348
...

© SecPod Technologies