Loading...
Loading...
The libxml_disable_entity_loader function in runtime/ext/ext_simplexml.cpp in HipHop Virtual Machine for PHP (HHVM) before 2.4.0 and 2.3.x before 2.3.3 does not properly disable a certain libxml handler, which allows remote attackers to conduct XML External Entity (XXE) attacks.
February 5, 2014
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2014-1439
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.