Lucene search

K
cvelistApacheCVELIST:CVE-2016-8734
HistoryOct 16, 2017 - 1:00 p.m.

CVE-2016-8734

2017-10-1613:00:00
apache
www.cve.org
8

AI Score

6.8

Confidence

High

EPSS

0.004

Percentile

73.1%

Apache Subversion’s mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

CNA Affected

[
  {
    "product": "Apache Subversion",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "1.4.0 to 1.8.16"
      },
      {
        "status": "affected",
        "version": "1.9.0 to 1.9.4"
      }
    ]
  }
]