← Back

CVE-2014-6259

nvd nist
Published: Dec 15, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka ZEN-15414, a similar issue to CVE-2003-1564.

Affected (20)

Products: Zenoss: Zenoss Core
1 product
Zenoss Core
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Zenoss
Up to 5.0.0
Version 2.4.0
Version 2.4.5
Version 2.5.0
Version 2.5.1
Version 2.5.2
Version 3.0.0
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.1.0
Version 3.2.0
Version 3.2.1
Version 4.2.0
Version 4.2.3
Version 4.2.4
Version 4.2.5
Version 5.0.0
Version 5.0.0 beta_1
Version 5.0.0 beta_2

Related CWEs

References (4)

Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.