Lucene search

K
cve[email protected]CVE-2014-9016
HistoryNov 24, 2014 - 3:59 p.m.

CVE-2014-9016

2014-11-2415:59:17
web.nvd.nist.gov
58
cve-2014-9016
drupal 7.x
password hashing api
dos
nvd
security vulnerability

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6 Medium

AI Score

Confidence

High

0.04 Low

EPSS

Percentile

92.1%

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

Affected configurations

NVD
Node
drupaldrupalRange7.07.34
OR
secure_password_hashes_projectsecure_passwords_hashesRange6.x-2.06.x-2.1drupal
Node
debiandebian_linuxMatch7.0

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6 Medium

AI Score

Confidence

High

0.04 Low

EPSS

Percentile

92.1%