CVE-2014-5266

Source
https://nvd.nist.gov/vuln/detail/CVE-2014-5266
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2014-5266.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2014-5266
Downstream
Published
2014-08-18T11:15:27Z
Modified
2025-08-09T20:01:27Z
Summary
[none]
Details

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

References

Affected packages