Vulnerability Name: | CVE-2014-9016 (CCN-98861) | ||||||||||||||||||||||||||||
Assigned: | 2014-11-20 | ||||||||||||||||||||||||||||
Published: | 2014-11-20 | ||||||||||||||||||||||||||||
Updated: | 2021-04-20 | ||||||||||||||||||||||||||||
Summary: | The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-9016 Source: CCN Type: oss-security Mailing List, Thu, 20 Nov 2014 07:10:28 +0100 Pending CVE assignments for SA-CORE-2014-006? Source: CCN Type: oss-security Mailing List, Thu, 20 Nov 2014 09:48:17 -0500 (EST) Re: Pending CVE assignments for SA-CORE-2014-006? Source: SECUNIA Type: Third Party Advisory 59164 Source: SECUNIA Type: Third Party Advisory 59814 Source: DEBIAN Type: Third Party Advisory DSA-3075 Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20141120 Re: [security] Pending CVE assignments for SA-CORE-2014-006? Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20141120 Pending CVE assignments for SA-CORE-2014-006? Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20141120 Re: [security] Pending CVE assignments for SA-CORE-2014-006? Source: CCN Type: BID-71195 Drupal Core CVE-2014-9015 Session Hijacking Vulnerability Source: XF Type: UNKNOWN drupalcore-cve20149016-dos(98861) Source: CCN Type: Packet Storm Security [12-01-2014] Drupal Memory Exhaustion Source: MISC Type: Patch, Vendor Advisory https://www.drupal.org/node/2378367 Source: CONFIRM Type: Patch, Vendor Advisory https://www.drupal.org/node/2378375 Source: CCN Type: DRUPAL-SA-CORE-2014-006 Drupal Core - Moderately Critical - Multiple Vulnerabilities Source: CONFIRM Type: Vendor Advisory https://www.drupal.org/SA-CORE-2014-006 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [12-01-2014] Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-9016 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |