Lucene search

K
cve[email protected]CVE-2016-9452
HistoryNov 25, 2016 - 6:59 p.m.

CVE-2016-9452

2016-11-2518:59:04
CWE-20
web.nvd.nist.gov
32
cve-2016-9452
drupal 8.x
denial of service
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.7%

The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.

Affected configurations

NVD
Node
drupaldrupalMatch8.0.0
OR
drupaldrupalMatch8.0.0alpha10
OR
drupaldrupalMatch8.0.0alpha11
OR
drupaldrupalMatch8.0.0alpha12
OR
drupaldrupalMatch8.0.0alpha13
OR
drupaldrupalMatch8.0.0alpha14
OR
drupaldrupalMatch8.0.0alpha15
OR
drupaldrupalMatch8.0.0alpha2
OR
drupaldrupalMatch8.0.0alpha3
OR
drupaldrupalMatch8.0.0alpha4
OR
drupaldrupalMatch8.0.0alpha5
OR
drupaldrupalMatch8.0.0alpha6
OR
drupaldrupalMatch8.0.0alpha7
OR
drupaldrupalMatch8.0.0alpha8
OR
drupaldrupalMatch8.0.0alpha9
OR
drupaldrupalMatch8.0.0beta1
OR
drupaldrupalMatch8.0.0beta10
OR
drupaldrupalMatch8.0.0beta11
OR
drupaldrupalMatch8.0.0beta12
OR
drupaldrupalMatch8.0.0beta13
OR
drupaldrupalMatch8.0.0beta14
OR
drupaldrupalMatch8.0.0beta15
OR
drupaldrupalMatch8.0.0beta16
OR
drupaldrupalMatch8.0.0beta2
OR
drupaldrupalMatch8.0.0beta3
OR
drupaldrupalMatch8.0.0beta4
OR
drupaldrupalMatch8.0.0beta6
OR
drupaldrupalMatch8.0.0beta7
OR
drupaldrupalMatch8.0.0beta9
OR
drupaldrupalMatch8.0.0rc1
OR
drupaldrupalMatch8.0.0rc2
OR
drupaldrupalMatch8.0.0rc3
OR
drupaldrupalMatch8.0.0rc4
OR
drupaldrupalMatch8.0.1
OR
drupaldrupalMatch8.0.2
OR
drupaldrupalMatch8.0.3
OR
drupaldrupalMatch8.0.4
OR
drupaldrupalMatch8.0.5
OR
drupaldrupalMatch8.0.6
OR
drupaldrupalMatch8.1.0
OR
drupaldrupalMatch8.1.0beta1
OR
drupaldrupalMatch8.1.0beta2
OR
drupaldrupalMatch8.1.0rc1
OR
drupaldrupalMatch8.1.1
OR
drupaldrupalMatch8.1.2
OR
drupaldrupalMatch8.1.3
OR
drupaldrupalMatch8.1.4
OR
drupaldrupalMatch8.1.5
OR
drupaldrupalMatch8.1.6
OR
drupaldrupalMatch8.1.7
OR
drupaldrupalMatch8.1.8
OR
drupaldrupalMatch8.1.9
OR
drupaldrupalMatch8.1.10
OR
drupaldrupalMatch8.2.0
OR
drupaldrupalMatch8.2.0beta1
OR
drupaldrupalMatch8.2.0beta2
OR
drupaldrupalMatch8.2.0beta3
OR
drupaldrupalMatch8.2.0rc1
OR
drupaldrupalMatch8.2.0rc2
OR
drupaldrupalMatch8.2.1
OR
drupaldrupalMatch8.2.2

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.7%