CVE-2014-501210.01.2020, 06:15DOMPDF before 0.6.2 allows denial of service.EnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST6.5 MEDIUMNETWORKLOWNONECVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HmitreCNA------CVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 34%VendorProductVersiondompdf_projectdompdf𝑥< 0.6.2𝑥= Vulnerable software versionsDebian ReleasesDebian ProductCodenamephp-dompdfbullseye0.6.2+dfsg-3.1fixedbookworm2.0.3+dfsg-1fixedsid3.0.0+dfsg-2fixedtrixie3.0.0+dfsg-2fixedUbuntu ReleasesUbuntu ProductCodenamephp-dompdflunardnekineticnot-affectedjammynot-affectedimpishnot-affectedhirsutenot-affectedgroovynot-affectedfocalnot-affectedeoannot-affecteddisconot-affectedcosmicnot-affectedbionicnot-affectedartfulignoredzestyignoredyakketyignoredxenialFixed 0.6.1+dfsg-2ubuntu1+esm1releasedwilyignoredtrustydneprecisedneReferenceshttps://github.com/dompdf/dompdf/compare/v0.6.1...v0.6.2https://github.com/dompdf/dompdf/releases/tag/v0.6.2https://github.com/dompdf/dompdf/compare/v0.6.1...v0.6.2https://github.com/dompdf/dompdf/releases/tag/v0.6.2