5
CVSSv2

CVE-2014-1439

Published: 05/02/2014 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The libxml_disable_entity_loader function in runtime/ext/ext_simplexml.cpp in HipHop Virtual Machine for PHP (HHVM) prior to 2.4.0 and 2.3.x prior to 2.3.3 does not properly disable a certain libxml handler, which allows remote malicious users to conduct XML External Entity (XXE) attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

hiphop virtual machine for php project hiphop virtual machine for php 2.0.1

hiphop virtual machine for php project hiphop virtual machine for php 2.0.0

hiphop virtual machine for php project hiphop virtual machine for php 2.3.0

hiphop virtual machine for php project hiphop virtual machine for php 2.2.0

hiphop virtual machine for php project hiphop virtual machine for php 2.1.0

hiphop virtual machine for php project hiphop virtual machine for php 2.0.2

hiphop virtual machine for php project hiphop virtual machine for php

hiphop virtual machine for php project hiphop virtual machine for php 2.3.1