CVE-2014-8080

Advisory lineage Upstream: 0 Downstream: 14
Modified
Published: 03 Nov 2014, 16:00
Last modified:06 Aug 2024, 13:10

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
15.63% MEDIUM
16% probability +4.84%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

03 Nov 2014, 16:00
Published
Vulnerability first disclosed
06 Aug 2024, 13:10
Last Modified
Vulnerability information updated

Description

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 15.63% Percentile: 95%

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 14.10

  • opensuseopensuse

    12.3 | 13.1

  • redhatenterprise_linux

    6.0 | 7.0

  • ruby-langruby

    ≤ 1.9.3 | 1.9.3 | 1.9.3:p0 | 1.9.3:p125 | 1.9.3:p194 | 1.9.3:p286 | 1.9.3:p383 | 1.9.3:p385 | 1.9.3:p392 | 1.9.3:p426 | 1.9.3:p429 | 1.9.3:p448 | 1.9.3:p545 | 1.9.3:p547 | 2.0.0 | 2.0.0:p0 | 2.0.0:p195 | 2.0.0:p247 | 2.0.0:p451 | 2.0.0:p481 | 2.0.0:p576 | 2.1.1 | 2.1.2 | 2.1.3

References (20)