Lucene search

K
cveRedhatCVE-2015-1819
HistoryAug 14, 2015 - 6:59 p.m.

CVE-2015-1819

2015-08-1418:59:03
CWE-399
redhat
web.nvd.nist.gov
152
xmlreader
libxml
denial of service
memory consumption
crafted xml data
xml entity expansion
xee
nvd
cve-2015-1819

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.5

Confidence

High

EPSS

0.025

Percentile

90.1%

The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.

Affected configurations

Nvd
Node
debiandebian_linuxMatch7.0
OR
debiandebian_linuxMatch8.0
Node
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch15.04
Node
redhatenterprise_linuxRange5.0
Node
xmlsoftlibxml
Node
oraclesolarisMatch11.3
Node
appleiphone_osRange9.2.1
OR
applemac_os_xRange10.11.3
OR
appletvosRange9.1
OR
applewatchosRange2.1
Node
oraclelinuxMatch7
Node
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
Node
fedoraprojectfedoraMatch22
OR
fedoraprojectfedoraMatch23
VendorProductVersionCPE
debiandebian_linux7.0cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
debiandebian_linux8.0cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
canonicalubuntu_linux12.04cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
canonicalubuntu_linux14.04cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
canonicalubuntu_linux15.04cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
redhatenterprise_linux*cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*
xmlsoftlibxml*cpe:2.3:a:xmlsoft:libxml:*:*:*:*:*:*:*:*
oraclesolaris11.3cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
appleiphone_os*cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
applemac_os_x*cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 171

References

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.5

Confidence

High

EPSS

0.025

Percentile

90.1%