Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.7"
},
{
"introduced": "0"
},
{
"last_affected": "1.5.8"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.8"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.9"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.10"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.11"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.12"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.13"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.14"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.15"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.16"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.17"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.18"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.19"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.20"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.21"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.23"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.7"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.8"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.9"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.10"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.11"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.12"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.13"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.14"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.15"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.16"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.17"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.18"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.19"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.20"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.7"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.8"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.9"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.10"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.11"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.12"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.13"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.14"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.15"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.16"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.4"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.4.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-8734.json"