CWE-776

Medium likelihood

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

Parent: CWE-674 - Uncontrolled Recursion

The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

86 vulnerabilities with CWE-776
CVE-2014-2228 CRITICAL
HP Fortify SCA <2.2 RC3 - Code Injection
CVSS 9.8
CVE-2013-4335 CRITICAL
opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6 - XML External Entity Injection
CVSS 9.8
CVE-2013-6461 MEDIUM
Nokogiri 1.5.0-1.5.10 - Denial of Service via XML Entity Expansion
CVSS 6.5
CVE-2013-6460 MEDIUM
Nokogiri 1.5.0-1.5.10 - Denial of Service via XML Entity Expansion
CVSS 6.5
CVE-2012-3340 MEDIUM
IBM InfoSphere Guardium 8.0, 8.01, 8.2 - Authenticated XML External Entity Injection
CVSS 4.3
CVE-2012-6685 HIGH
Nokogiri < 1.5.4 - XML External Entity Injection
CVSS 7.5
CVE-2011-3288 HIGH
Cisco Unified Presence < 8.5(4) - Denial of Service via XML Entity Expansion
CVSS 7.5
CVE-2011-1755 HIGH
jabberd2 < 2.2.14 - Denial of Service via XML Entity Expansion
CVSS 7.5
CVE-2009-1955 HIGH
Apache APR-util < 1.3.7 - Denial of Service via XML Entity Expansion
CVSS 7.5
CVE-2008-3281 MEDIUM
libxml2 < 2.6.32 - Denial of Service via Recursive Entity Expansion in DTDs
CVSS 6.5
CVE-2003-1564 MEDIUM
libxml2 < 2.5.0 - Denial of Service via Recursive Entity Expansion
CVSS 6.5
Details
Vulnerabilities 86
Exploit Likelihood Medium