CVE-2014-3005

Source
https://nvd.nist.gov/vuln/detail/CVE-2014-3005
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2014-3005.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2014-3005
Downstream
Related
Published
2018-02-01T17:29:00Z
Modified
2025-08-09T20:01:25Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.

References

Affected packages