Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-8567

24
FAUCET Score

CVE-2014-8567 describes a denial-of-service vulnerability in the mod_auth_mellon module, affecting versions prior to 0.8.1, specifically impacting Red Hat and UNINETT deployments. A remote attacker can crash the Apache HTTP server by sending a specially crafted logout request, leading to a read of uninitialized data. This vulnerability carries a critical CVSS score of 9.4, indicating a network-based attack with low complexity and high impact on availability and integrity. Despite its severity, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.8.1CPE matchmatch criteria
cpe:2.3:a:uninett:mod_auth_mellon:*:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
6.6CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.6:*:*:*:*:*:*:*
6.6CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_server_eus:6.6:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.4HIGH

AV:N/AC:L/Au:N/C:N/I:C/A:C

Confidentiality Impact
NONE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
9.2
CvssVersion
2.0

Exploit Intelligence

EPSS Score
3.59%
Probability of exploitation in next 30 days
EPSS Percentile
88.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0359 is in the 79th percentile among its peer group of 51,466 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: mod_auth_mellon-0:0.8.0-3.el6_6
View patch

Vendor Advisories (1)

redhatCVE-2014-8567Moderate

mod_auth_mellon: logout processing leads to denial of service

Nov 3, 2014

References

linux.oracle.com / errata/ELSA-2014-1803.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-1803.html
Third Party Advisory
secunia.com / advisories/62094
Permissions RequiredThird Party Advisory
secunia.com / advisories/62125
Permissions RequiredThird Party Advisory
github.com / UNINETT/mod_auth_mellon/commit/0f5b4fd860fa7e3a6c47201637aab05395f32647
Third Party Advisory
postlister.uninett.no / sympa/arc/modmellon/2014-11/msg00000.html
Vendor Advisory