← Vulnerability feed

Vulnerability record · CVE-2014-2683 · published 16 November 2014

CVE-2014-2683: Zendrest vulnerability

Zend · Zendrest

Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to cause a denial of service (CPU consumption) via (1) recursive or (2) circular references in an XML entity definition in an XML DOCTYPE declaration, aka an XML Entity Expansion (XEE) attack. NOTE: this issue exists because of an incomplete fix for CVE-2012-6532.

5.0 CVSS 2.0 Medium EPSS 2.4% · top 17.0% CWE-17 · CWE-17
5.0CVSS 2.0 base score
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to cause a denial of service (CPU consumption) via (1) recursive or (2) circular references in an XML entity definition in an XML DOCTYPE declaration, aka an XML Entity Expansion (XEE) attack. NOTE: this issue exists because of an incomplete fix for CVE-2012-6532.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2683 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-29312Zend framework deserialization of untrusted data vulnerabilityAn issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has be…EPSS 1.3%9.8CVE-2021-3007Laminas-http and Zend Framework PHP deserialization RCELaminas-http before 2.14.2 and Zend Framework 3.0.0 contain a PHP object deserialization flaw tied to the __destruct method of Zend\Http\Response\Str…EPSS 75%analysed9.8CVE-2014-8089Zend framework sql injection vulnerabilitySQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows …EPSS 2.6%9.8CVE-2011-1939Zend framework sql injection vulnerabilitySQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction …EPSS 3.9%9.8CVE-2014-4914Zend framework sql injection vulnerabilityThe Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL…EPSS 2.3%9.8CVE-2016-4861Fedoraproject fedora sql injection vulnerabilityThe (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection atta…EPSS 4.1%9.8CVE-2016-6233Fedoraproject fedora sql injection vulnerabilityThe (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection atta…EPSS 2.0%9.8CVE-2016-10034Zend framework command injection vulnerabilityThe setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework befor…EPSS 38%

Source: NIST National Vulnerability Database (record CVE-2014-2683), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.