5

CVE-2014-5265

WordPress Core < 3.9.2 - Denial of Service via XML

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Mögliche Gegenmaßnahme
WordPress: Update to one of the following versions, or a newer patched version: 3.7.4, 3.8.4, 3.9.2
Weitere Schwachstelleninformationen
SystemWordPress Core
Produkt WordPress
Version [*, 3.7)
Version 3.7 - 3.7.3
Version 3.8 - 3.8.3
Version 3.9 - 3.9.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WordpressWordpress Version <= 3.9.1
WordpressWordpress Version3.0
WordpressWordpress Version3.0.1
WordpressWordpress Version3.0.2
WordpressWordpress Version3.0.3
WordpressWordpress Version3.0.4
WordpressWordpress Version3.0.5
WordpressWordpress Version3.0.6
WordpressWordpress Version3.1
WordpressWordpress Version3.1.1
WordpressWordpress Version3.1.2
WordpressWordpress Version3.1.3
WordpressWordpress Version3.1.4
WordpressWordpress Version3.2
WordpressWordpress Version3.2 Updatebeta1
WordpressWordpress Version3.2.1
WordpressWordpress Version3.3
WordpressWordpress Version3.3.1
WordpressWordpress Version3.3.2
WordpressWordpress Version3.3.3
WordpressWordpress Version3.4.0
WordpressWordpress Version3.4.1
WordpressWordpress Version3.4.2
WordpressWordpress Version3.5.0
WordpressWordpress Version3.5.1
WordpressWordpress Version3.6
WordpressWordpress Version3.6.1
WordpressWordpress Version3.7
WordpressWordpress Version3.7.1
WordpressWordpress Version3.8
WordpressWordpress Version3.8.1
WordpressWordpress Version3.9.0
DrupalDrupal Version6.0
DrupalDrupal Version6.0 Updatebeta1
DrupalDrupal Version6.0 Updatebeta2
DrupalDrupal Version6.0 Updatebeta3
DrupalDrupal Version6.0 Updatebeta4
DrupalDrupal Version6.0 Updatedev
DrupalDrupal Version6.0 Updaterc1
DrupalDrupal Version6.0 Updaterc2
DrupalDrupal Version6.0 Updaterc3
DrupalDrupal Version6.0 Updaterc4
DrupalDrupal Version6.1
DrupalDrupal Version6.2
DrupalDrupal Version6.3
DrupalDrupal Version6.4
DrupalDrupal Version6.5
DrupalDrupal Version6.6
DrupalDrupal Version6.7
DrupalDrupal Version6.8
DrupalDrupal Version6.9
DrupalDrupal Version6.10
DrupalDrupal Version6.11
DrupalDrupal Version6.12
DrupalDrupal Version6.13
DrupalDrupal Version6.14
DrupalDrupal Version6.15
DrupalDrupal Version6.16
DrupalDrupal Version6.17
DrupalDrupal Version6.18
DrupalDrupal Version6.19
DrupalDrupal Version6.20
DrupalDrupal Version6.21
DrupalDrupal Version6.22
DrupalDrupal Version6.23
DrupalDrupal Version6.24
DrupalDrupal Version6.25
DrupalDrupal Version6.26
DrupalDrupal Version6.27
DrupalDrupal Version6.28
DrupalDrupal Version6.29
DrupalDrupal Version6.30
DrupalDrupal Version6.31
DrupalDrupal Version6.32
DrupalDrupal Version7.0
DrupalDrupal Version7.0 Updatealpha1
DrupalDrupal Version7.0 Updatealpha2
DrupalDrupal Version7.0 Updatealpha3
DrupalDrupal Version7.0 Updatealpha4
DrupalDrupal Version7.0 Updatealpha5
DrupalDrupal Version7.0 Updatealpha6
DrupalDrupal Version7.0 Updatealpha7
DrupalDrupal Version7.0 Updatebeta1
DrupalDrupal Version7.0 Updatebeta2
DrupalDrupal Version7.0 Updatebeta3
DrupalDrupal Version7.0 Updatedev
DrupalDrupal Version7.0 Updaterc1
DrupalDrupal Version7.0 Updaterc2
DrupalDrupal Version7.0 Updaterc3
DrupalDrupal Version7.0 Updaterc4
DrupalDrupal Version7.1
DrupalDrupal Version7.2
DrupalDrupal Version7.3
DrupalDrupal Version7.4
DrupalDrupal Version7.5
DrupalDrupal Version7.6
DrupalDrupal Version7.7
DrupalDrupal Version7.8
DrupalDrupal Version7.9
DrupalDrupal Version7.10
DrupalDrupal Version7.11
DrupalDrupal Version7.12
DrupalDrupal Version7.13
DrupalDrupal Version7.14
DrupalDrupal Version7.15
DrupalDrupal Version7.16
DrupalDrupal Version7.17
DrupalDrupal Version7.18
DrupalDrupal Version7.19
DrupalDrupal Version7.20
DrupalDrupal Version7.21
DrupalDrupal Version7.22
DrupalDrupal Version7.23
DrupalDrupal Version7.24
DrupalDrupal Version7.25
DrupalDrupal Version7.26
DrupalDrupal Version7.27
DrupalDrupal Version7.28
DrupalDrupal Version7.29
DrupalDrupal Version7.30
DrupalDrupal Version7.x-dev
DebianDebian Linux Version7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.02% 0.911
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P