296,746
Total vulnerabilities in the database
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
| Software | From | Fixed in |
|---|---|---|
| apache / apr-util | - | 1.3.7 |
| apple / mac_os_x | - | 10.6.2 |
| suse / linux_enterprise_server | 9 | 9.x |
| debian / debian_linux | 4.0 | 4.0.x |
| canonical / ubuntu_linux | 9.04 | 9.04.x |
| canonical / ubuntu_linux | 8.10 | 8.10.x |
| canonical / ubuntu_linux | 8.04 | 8.04.x |
| canonical / ubuntu_linux | 6.06 | 6.06.x |
| fedoraproject / fedora | 11 | 11.x |
| fedoraproject / fedora | 10 | 10.x |
| fedoraproject / fedora | 9 | 9.x |
| apache / http_server | 2.2.0 | 2.2.12 |