VYPR

REXML

by Ruby Lang

gem: REXML

CVEs (2)

  • CVE-2008-3790Aug 27, 2008
    risk 0.04cvss epss 0.15

    The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an "XML entity explosion."

  • CVE-2014-8080Nov 3, 2014
    risk 0.00cvss epss 0.05

    The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.