Vulnerabilities
Vulnerable Software
Xmlsoft:  >> Libxml2  >> 1.8.14  Security Vulnerabilities
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
CVSS Score
6.5
EPSS Score
0.008
Published
2008-08-27
libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."
CVSS Score
6.5
EPSS Score
0.009
Published
2003-12-31


Contact Us

Shodan ® - All rights reserved