← Back

CVE-2014-8080

nvd nist
Published: Nov 3, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

Affected (31)

Products: Opensuse: Opensuse · Canonical: Ubuntu Linux · Ruby Lang: Ruby · +1 more
Show all products
1 product
Opensuse
1 product
Ubuntu Linux
1 product
Ruby
1 product
Enterprise Linux
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 12.3
Version 13.1
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 14.10
Configuration C
24 vulnerable
Vulnerable SoftwareAffected Versions
Ruby Lang
Up to 1.9.3
Version 1.9.3
Version 1.9.3 p0
Version 1.9.3 p125
Version 1.9.3 p194
Version 1.9.3 p286
Version 1.9.3 p383
Version 1.9.3 p385
Version 1.9.3 p392
Version 1.9.3 p426
Version 1.9.3 p429
Version 1.9.3 p448
Version 1.9.3 p545
Version 1.9.3 p547
Version 2.0.0
Version 2.0.0 p0
Version 2.0.0 p195
Version 2.0.0 p247
Version 2.0.0 p451
Version 2.0.0 p481
Version 2.0.0 p576
Version 2.1.1
Version 2.1.2
Version 2.1.3
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 6.0
Version 7.0

References (40)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory

Timeline

No history available yet.