5
CVSSv2

CVE-2012-6532

Published: 13/02/2013 Updated: 04/05/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

(1) Zend_Dom, (2) Zend_Feed, (3) Zend_Soap, and (4) Zend_XmlRpc in Zend Framework 1.x prior to 1.11.13 and 1.12.x prior to 1.12.0 allow remote malicious users to cause a denial of service (CPU consumption) via recursive or circular references in an XML entity definition in an XML DOCTYPE declaration, aka an XML Entity Expansion (XEE) attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zend zend framework 1.0.4

zend zend framework 1.7.0

zend zend framework 1.7.1

zend zend framework 1.7.8

zend zend framework 1.7.9

zend zend framework 1.9.0

zend zend framework 1.9.1

zend zend framework 1.10.0

zend zend framework 1.10.1

zend zend framework 1.10.8

zend zend framework 1.11.0

zend zend framework 1.5.0

zend zend framework 1.5.1

zend zend framework 1.5.2

zend zend framework 1.7.2

zend zend framework 1.7.3

zend zend framework 1.8.0

zend zend framework 1.8.1

zend zend framework 1.9.2

zend zend framework 1.9.3

zend zend framework 1.9.4

zend zend framework 1.10.2

zend zend framework 1.10.3

zend zend framework 1.11.1

zend zend framework 1.11.2

zend zend framework 1.11.10

zend zend framework 1.11.11

zend zend framework 1.6.1

zend zend framework 1.6.2

zend zend framework 1.7.6

zend zend framework 1.7.7

zend zend framework 1.8.4

zend zend framework 1.8.5

zend zend framework 1.9.7

zend zend framework 1.9.8

zend zend framework 1.10.6

zend zend framework 1.10.7

zend zend framework 1.11.5

zend zend framework 1.11.6

zend zend framework 1.12.0

zend zend framework 1.11.7

zend zend framework 1.11.8

zend zend framework 1.11.9

zend zend framework 1.5.3

zend zend framework 1.6.0

zend zend framework 1.7.4

zend zend framework 1.7.5

zend zend framework 1.8.2

zend zend framework 1.8.3

zend zend framework 1.9.5

zend zend framework 1.9.6

zend zend framework 1.10.4

zend zend framework 1.10.5

zend zend framework 1.11.3

zend zend framework 1.11.4

zend zend framework 1.11.12

Vendor Advisories

Debian Bug report logs - #743175 zendframework: two security issues Package: zendframework; Maintainer for zendframework is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Source for zendframework is src:zendframework (PTS, buildd, popcon) Reported by: "Thijs Kinkhorst" <thijs@debianorg> Date: Mo ...
Multiple vulnerabilities were discovered in Zend Framework, a PHP framework Except for CVE-2015-3154, all these issues were already fixed in the version initially shipped with Jessie CVE-2014-2681 Lukas Reschke reported a lack of protection against XML External Entity injection attacks in some functions This fix extends the incomple ...