Логотип exploitDog
bind:"CVE-2014-8090"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2014-8090"

Количество 8

Количество 8

ubuntu логотип

CVE-2014-8090

почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2014-8090

почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-8090

почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-8090

почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x befo ...

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-2x97-vvh4-m4q4

больше 3 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

EPSS: Низкий
oracle-oval логотип

ELSA-2014-1911

почти 11 лет назад

ELSA-2014-1911: ruby security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2014-1913

больше 9 лет назад

ELSA-2014-1913: ruby193-ruby security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2014-1912

почти 11 лет назад

ELSA-2014-1912: ruby security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-8090

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

CVSS2: 5
9%
Низкий
почти 11 лет назад
redhat логотип
CVE-2014-8090

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

CVSS2: 4.3
9%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-8090

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

CVSS2: 5
9%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-8090

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x befo ...

CVSS2: 5
9%
Низкий
почти 11 лет назад
github логотип
GHSA-2x97-vvh4-m4q4

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

9%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2014-1911

ELSA-2014-1911: ruby security update (MODERATE)

почти 11 лет назад
oracle-oval логотип
ELSA-2014-1913

ELSA-2014-1913: ruby193-ruby security update (MODERATE)

больше 9 лет назад
oracle-oval логотип
ELSA-2014-1912

ELSA-2014-1912: ruby security update (MODERATE)

почти 11 лет назад

Уязвимостей на страницу