V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-8080
DEB
Medium

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial…

CVSS
4.3
Medium
EPSS
0.05
p91
Published
2014-01-01
Updated
2014-01-01
Description

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

Tags · CWE
CWE-776
CAPEC-197
Affected products
RubyRubyRuby1.8Ruby1.9.1Ruby1.9.1Ruby1.9.1Ruby1.9.1Ruby193-rubyRuby193-rubyRuby193-rubyRuby193-rubyRuby193-rubyRuby2.0Ruby2.0Ruby2.0Ruby2.1Ruby2.1Ruby2.1Ruby2.1Ruby200-ruby
CVSS vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.055 · p91
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
rubyTracked
rubyTracked
ruby1.8Tracked
ruby1.9.1Tracked
ruby1.9.1Tracked
ruby1.9.1Tracked
ruby1.9.1Tracked
ruby193-rubyTracked
ruby193-rubyTracked
ruby193-rubyTracked
ruby193-rubyTracked
ruby193-rubyTracked
ruby2.0Tracked
ruby2.0Tracked
ruby2.0Tracked
ruby2.1Tracked
ruby2.1Tracked
ruby2.1Tracked
ruby2.1Tracked
ruby200-rubyTracked
Showing first 20 of 28
Source databases
DEB
CVE
RED
UBU