Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2014-3660

parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.

  • Published: Nov 4, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-3660
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P

No CWE or OWASP classifications available.

Software From Fixed in
xmlsoft / libxml2 2.2.0 2.2.0.x
xmlsoft / libxml2 2.2.2 2.2.2.x
xmlsoft / libxml2 2.4.30 2.4.30.x
xmlsoft / libxml2 2.6.16 2.6.16.x
xmlsoft / libxml2 2.6.32 2.6.32.x
xmlsoft / libxml2 2.1.0 2.1.0.x
xmlsoft / libxml2 2.6.29 2.6.29.x
xmlsoft / libxml2 2.4.19 2.4.19.x
xmlsoft / libxml2 2.4.7 2.4.7.x
xmlsoft / libxml2 2.4.17 2.4.17.x
xmlsoft / libxml2 2.2.9 2.2.9.x
xmlsoft / libxml2 2.8.0 2.8.0.x
xmlsoft / libxml2 2.3.6 2.3.6.x
xmlsoft / libxml2 2.6.26 2.6.26.x
xmlsoft / libxml2 2.6.11 2.6.11.x
xmlsoft / libxml2 2.7.2 2.7.2.x
xmlsoft / libxml2 2.4.21 2.4.21.x
xmlsoft / libxml2 2.4.20 2.4.20.x
xmlsoft / libxml2 2.3.7 2.3.7.x
xmlsoft / libxml2 2.6.17 2.6.17.x
xmlsoft / libxml2 2.2.4 2.2.4.x
xmlsoft / libxml2 2.4.25 2.4.25.x
xmlsoft / libxml2 2.4.24 2.4.24.x
xmlsoft / libxml2 2.5.0 2.5.0.x
xmlsoft / libxml2 2.4.6 2.4.6.x
xmlsoft / libxml2 2.4.12 2.4.12.x
xmlsoft / libxml2 2.3.8 2.3.8.x
xmlsoft / libxml2 2.6.27 2.6.27.x
xmlsoft / libxml2 2.3.13 2.3.13.x
xmlsoft / libxml2 2.3.14 2.3.14.x
xmlsoft / libxml2 2.1.1 2.1.1.x
xmlsoft / libxml2 2.2.6 2.2.6.x
xmlsoft / libxml2 2.2.10 2.2.10.x
xmlsoft / libxml2 2.4.13 2.4.13.x
xmlsoft / libxml2 2.3.1 2.3.1.x
xmlsoft / libxml2 2.6.13 2.6.13.x
xmlsoft / libxml2 2.7.8 2.7.8.x
xmlsoft / libxml2 2.7.7 2.7.7.x
xmlsoft / libxml2 2.6.7 2.6.7.x
xmlsoft / libxml2 2.6.14 2.6.14.x
xmlsoft / libxml2 2.4.27 2.4.27.x
xmlsoft / libxml2 2.4.18 2.4.18.x
xmlsoft / libxml2 2.5.7 2.5.7.x
xmlsoft / libxml2 2.3.0 2.3.0.x
xmlsoft / libxml2 2.4.10 2.4.10.x
xmlsoft / libxml2 2.9.0 2.9.0.x
xmlsoft / libxml2 2.4.26 2.4.26.x
xmlsoft / libxml2 2.5.8 2.5.8.x
xmlsoft / libxml2 2.4.28 2.4.28.x
xmlsoft / libxml2 2.3.3 2.3.3.x
xmlsoft / libxml2 2.2.8 2.2.8.x
xmlsoft / libxml2 2.6.23 2.6.23.x
xmlsoft / libxml2 2.4.9 2.4.9.x
xmlsoft / libxml2 2.4.5 2.4.5.x
xmlsoft / libxml2 2.4.8 2.4.8.x
xmlsoft / libxml2 2.6.8 2.6.8.x
xmlsoft / libxml2 2.4.15 2.4.15.x
xmlsoft / libxml2 2.4.11 2.4.11.x
xmlsoft / libxml2 2.6.2 2.6.2.x
xmlsoft / libxml2 2.9.0-rc1 2.9.0-rc1.x
xmlsoft / libxml2 2.2.7 2.2.7.x
xmlsoft / libxml2 2.2.5 2.2.5.x
xmlsoft / libxml2 2.2.3 2.2.3.x
xmlsoft / libxml2 2.4.22 2.4.22.x
xmlsoft / libxml2 2.6.5 2.6.5.x
xmlsoft / libxml2 2.6.4 2.6.4.x
xmlsoft / libxml2 2.7.5 2.7.5.x
xmlsoft / libxml2 2.6.18 2.6.18.x
xmlsoft / libxml2 2.4.16 2.4.16.x
xmlsoft / libxml2 2.5.11 2.5.11.x
xmlsoft / libxml2 2.6.24 2.6.24.x
xmlsoft / libxml2 2.3.5 2.3.5.x
xmlsoft / libxml2 2.0.0 2.0.0.x
xmlsoft / libxml2 2.3.10 2.3.10.x
xmlsoft / libxml2 2.4.2 2.4.2.x
xmlsoft / libxml2 2.7.3 2.7.3.x
xmlsoft / libxml2 2.3.4 2.3.4.x
xmlsoft / libxml2 2.2.0-beta 2.2.0-beta.x
xmlsoft / libxml2 2.6.1 2.6.1.x
xmlsoft / libxml2 2.6.20 2.6.20.x
xmlsoft / libxml2 2.6.31 2.6.31.x
xmlsoft / libxml2 2.7.1 2.7.1.x
xmlsoft / libxml2 2.2.1 2.2.1.x
xmlsoft / libxml2 - 2.9.1.x
xmlsoft / libxml2 2.7.0 2.7.0.x
xmlsoft / libxml2 2.6.21 2.6.21.x
xmlsoft / libxml2 2.7.6 2.7.6.x
xmlsoft / libxml2 2.3.9 2.3.9.x
xmlsoft / libxml2 2.4.1 2.4.1.x
xmlsoft / libxml2 2.4.23 2.4.23.x
xmlsoft / libxml2 2.6.12 2.6.12.x
xmlsoft / libxml2 2.6.0 2.6.0.x
xmlsoft / libxml2 2.6.25 2.6.25.x
xmlsoft / libxml2 2.6.9 2.6.9.x
xmlsoft / libxml2 2.5.4 2.5.4.x
xmlsoft / libxml2 2.6.30 2.6.30.x
xmlsoft / libxml2 2.3.11 2.3.11.x
xmlsoft / libxml2 2.4.3 2.4.3.x
xmlsoft / libxml2 2.7.4 2.7.4.x
xmlsoft / libxml2 2.6.28 2.6.28.x
xmlsoft / libxml2 2.5.10 2.5.10.x
xmlsoft / libxml2 2.3.12 2.3.12.x
xmlsoft / libxml2 2.4.4 2.4.4.x
xmlsoft / libxml2 2.4.14 2.4.14.x
xmlsoft / libxml2 2.6.22 2.6.22.x
xmlsoft / libxml2 2.3.2 2.3.2.x
xmlsoft / libxml2 2.6.3 2.6.3.x
xmlsoft / libxml2 2.2.11 2.2.11.x
xmlsoft / libxml2 2.4.29 2.4.29.x
xmlsoft / libxml2 2.6.6 2.6.6.x
canonical / ubuntu_linux 12.04 12.04.x
debian / debian_linux 7.0 7.0.x
canonical / ubuntu_linux 14.04 14.04.x
redhat / enterprise_linux 5.0 5.0.x
canonical / ubuntu_linux 10.04 10.04.x
apple / mac_os_x - 10.10.4.x