Lucene search

K
friendsofphpOpenJS FoundationFRIENDSOFPHP:JAMES-HEINRICH:GETID3:CVE-2014-2053
HistorySep 14, 2014 - 6:13 p.m.

Potential XXE security issue

2014-09-1418:13:30
OpenJS Foundation
github.com
9

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.007

Percentile

80.8%

improved XXE fix (CVE-2014-2053)

Affected configurations

Vulners
Node
james-heinrichgetid3Range<1.9.9
VendorProductVersionCPE
james-heinrichgetid3*cpe:2.3:a:james-heinrich:getid3:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.007

Percentile

80.8%