« Volver al listado

CVE-2014-1439

Estado: ModificadaMedia (5)—

The libxml_disable_entity_loader function in runtime/ext/ext_simplexml.cpp in HipHop Virtual Machine for PHP (HHVM) before 2.4.0 and 2.3.x before 2.3.3 does not properly disable a certain libxml handler, which allows remote attackers to conduct XML External Entity (XXE) attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-1439",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-02-05T19:55:28.873",
  "references": [
    {
      "url": "http://www.hhvm.com/blog/3287/hhvm-2-4-0",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/90979",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/facebook/hhvm/commit/95f96e7287effe2fcdfb9a5338d1a7e4f55b083b",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.hhvm.com/blog/3287/hhvm-2-4-0",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/90979",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/facebook/hhvm/commit/95f96e7287effe2fcdfb9a5338d1a7e4f55b083b",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The libxml_disable_entity_loader function in runtime/ext/ext_simplexml.cpp in HipHop Virtual Machine for PHP (HHVM) before 2.4.0 and 2.3.x before 2.3.3 does not properly disable a certain libxml handler, which allows remote attackers to conduct XML External Entity (XXE) attacks."
    },
    {
      "lang": "es",
      "value": "La función libxml_disable_entity_loader en runtime/ext/ext_simplexml.cpp en HipHop Virtual Machine para PHP (HHVM) anterior a  2.4.0 y 2.3.x anterior a 2.3.3 no deshabilita debidamente cierto manejador libxml, lo que permite a atacantes remotos llevar a cabo ataques de entidades externas XML (XXE)."
    }
  ],
  "lastModified": "2026-06-17T00:04:53.633",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hiphop_virtual_machine_for_php_project:hiphop_virtual_machine_for_php:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABE96C2D-5511-462E-AFFF-DF842136E7F5",
              "versionEndIncluding": "2.3.2"
            },
            {
              "criteria": "cpe:2.3:a:hiphop_virtual_machine_for_php_project:hiphop_virtual_machine_for_php:2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87A21C9E-E90D-46D5-B2F9-BC47F81D8CD3"
            },
            {
              "criteria": "cpe:2.3:a:hiphop_virtual_machine_for_php_project:hiphop_virtual_machine_for_php:2.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA3F4287-9D9F-47B1-8232-93800FB0AB17"
            },
            {
              "criteria": "cpe:2.3:a:hiphop_virtual_machine_for_php_project:hiphop_virtual_machine_for_php:2.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C6CBE0C2-7CE9-40D7-B8BF-B673A2C2826F"
            },
            {
              "criteria": "cpe:2.3:a:hiphop_virtual_machine_for_php_project:hiphop_virtual_machine_for_php:2.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C81C665-2957-4409-9FB6-A5BF072AE094"
            },
            {
              "criteria": "cpe:2.3:a:hiphop_virtual_machine_for_php_project:hiphop_virtual_machine_for_php:2.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F2C0B758-D770-4190-A3BF-643C1F0413D4"
            },
            {
              "criteria": "cpe:2.3:a:hiphop_virtual_machine_for_php_project:hiphop_virtual_machine_for_php:2.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D4A33BF-1010-4524-ACFE-805A0C779C0A"
            },
            {
              "criteria": "cpe:2.3:a:hiphop_virtual_machine_for_php_project:hiphop_virtual_machine_for_php:2.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2792D0E7-17EC-44A2-9E8A-E0E4CDA45A6F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "CWE-611: Improper Restriction of XML External Entity Reference ('XXE')",
  "sourceIdentifier": "cve@mitre.org"
}