{"api_version":"1","generated_at":"2026-07-23T09:52:55+00:00","cve":"CVE-2014-0191","urls":{"html":"https://cve.report/CVE-2014-0191","api":"https://cve.report/api/cve/CVE-2014-0191.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-0191","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-0191"},"summary":{"title":"CVE-2014-0191","description":"The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.","state":"PUBLISHED","assigner":"redhat","published_at":"2015-01-21 14:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://xmlsoft.org/news.html","name":"http://xmlsoft.org/news.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Releases","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html","name":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2015-08-13-2 OS X Yosemite v10.10.5 and Security Update\t2015-006","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/kb/HT205031","name":"https://support.apple.com/kb/HT205031","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0749.html","name":"http://rhn.redhat.com/errata/RHSA-2015-0749.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html","name":"http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Critical Patch Update - October 2015","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1090976","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1090976","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"1090976 – (CVE-2014-0191) CVE-2014-0191 libxml2: external parameter entity loaded when entity substitution is disabled","mime":"text/html","httpstatus":"200","archivestatus":"503"},{"url":"https://git.gnome.org/browse/libxml2/commit/?id=9cd1c3cfbd32655d60572c0a413e017260c854df","name":"https://git.gnome.org/browse/libxml2/commit/?id=9cd1c3cfbd32655d60572c0a413e017260c854df","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"libxml2 - XML parser and markup toolkit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21678183","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21678183","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Security Bulletin: Rational Systems Tester is affected by Libxml2 vulnerability (CVE-2014-0191) - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/67233","name":"http://www.securityfocus.com/bid/67233","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Libxml2 Entity Substituton CVE-2014-0191 Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://support.apple.com/kb/HT205030","name":"https://support.apple.com/kb/HT205030","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of iOS 8.4.1 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","name":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2015-08-13-3 iOS 8.4.1","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/93092","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/93092","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","name":"http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Oracle Critical Patch Update - January 2015","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html","name":"http://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"openSUSE-SU-2015:2372-1: moderate: Security update for libxml2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-0191","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0191","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"191","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"fusion_middleware","cpe6":"11.1.1.7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"191","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"fusion_middleware","cpe6":"12.1.2.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"191","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"fusion_middleware","cpe6":"12.1.3.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T09:05:39.238Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1090976"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/kb/HT205030"},{"name":"67233","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/67233"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://xmlsoft.org/news.html"},{"name":"RHSA-2015:0749","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0749.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://git.gnome.org/browse/libxml2/commit/?id=9cd1c3cfbd32655d60572c0a413e017260c854df"},{"name":"libxml2-cve20140191-dos(93092)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/93092"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21678183"},{"name":"APPLE-SA-2015-08-13-2","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html"},{"name":"APPLE-SA-2015-08-13-3","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html"},{"name":"openSUSE-SU-2015:2372","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/kb/HT205031"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-05-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1090976"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/kb/HT205030"},{"name":"67233","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/67233"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://xmlsoft.org/news.html"},{"name":"RHSA-2015:0749","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0749.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://git.gnome.org/browse/libxml2/commit/?id=9cd1c3cfbd32655d60572c0a413e017260c854df"},{"name":"libxml2-cve20140191-dos(93092)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/93092"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21678183"},{"name":"APPLE-SA-2015-08-13-2","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html"},{"name":"APPLE-SA-2015-08-13-3","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html"},{"name":"openSUSE-SU-2015:2372","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/kb/HT205031"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2014-0191","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=1090976","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1090976"},{"name":"https://support.apple.com/kb/HT205030","refsource":"CONFIRM","url":"https://support.apple.com/kb/HT205030"},{"name":"67233","refsource":"BID","url":"http://www.securityfocus.com/bid/67233"},{"name":"http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html"},{"name":"http://xmlsoft.org/news.html","refsource":"CONFIRM","url":"http://xmlsoft.org/news.html"},{"name":"RHSA-2015:0749","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-0749.html"},{"name":"http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html"},{"name":"https://git.gnome.org/browse/libxml2/commit/?id=9cd1c3cfbd32655d60572c0a413e017260c854df","refsource":"CONFIRM","url":"https://git.gnome.org/browse/libxml2/commit/?id=9cd1c3cfbd32655d60572c0a413e017260c854df"},{"name":"libxml2-cve20140191-dos(93092)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/93092"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21678183","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21678183"},{"name":"APPLE-SA-2015-08-13-2","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html"},{"name":"APPLE-SA-2015-08-13-3","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html"},{"name":"openSUSE-SU-2015:2372","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2015-12/msg00120.html"},{"name":"https://support.apple.com/kb/HT205031","refsource":"CONFIRM","url":"https://support.apple.com/kb/HT205031"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2014-0191","datePublished":"2015-01-21T02:00:00.000Z","dateReserved":"2013-12-03T00:00:00.000Z","dateUpdated":"2024-08-06T09:05:39.238Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-01-21 14:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:fusion_middleware:11.1.1.7.0:*:*:*:*:*:*:*","matchCriteriaId":"E8934DB1-B2A1-4C3B-B000-78826FC45C7C"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:fusion_middleware:12.1.2.0.0:*:*:*:*:*:*:*","matchCriteriaId":"D4E67774-F4FB-4EA3-A527-92EF41F84248"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:fusion_middleware:12.1.3.0.0:*:*:*:*:*:*:*","matchCriteriaId":"97E1C55E-7A74-40F1-9C52-D84A5F55CD96"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"191","Ordinal":"1","Title":"CVE-2014-0191","CVE":"CVE-2014-0191","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"191","Ordinal":"1","NoteData":"The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.","Type":"Description","Title":"CVE-2014-0191"},{"CveYear":"2014","CveId":"191","Ordinal":"2","NoteData":"2015-01-20","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"191","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}