CVE-2014-0191 is a denial-of-service vulnerability in libxml2, specifically within the xmlParserHandlePEReference function, which affects products like Oracle HTTP Server in Oracle Fusion Middleware. It allows remote attackers to trigger resource exhaustion by submitting a crafted XML document that forces the loading of external parameter entities. With a CVSS score of 4.3, this vulnerability has a network attack vector, medium attack complexity, and results in partial availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:11.1.1.7.0:*:*:*:*:*:*:* | ||
12.1.2.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:12.1.2.0.0:*:*:*:*:*:*:* | ||
12.1.3.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:12.1.3.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.