The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T11:41:47.672Z
Reserved: 2014-08-15T00:00:00
Link: CVE-2014-5266

No data.

Status : Deferred
Published: 2014-08-18T11:15:27.497
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-5266

No data.

No data.