V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2011-1944
DEB
MediumConfirmedExploit available

Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependen…

CVSS
5.1
Medium
EPSS
0.24
p96
Published
2011-01-01
Updated
2011-01-01
Description

Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.

Tags · CWE
CWE-122
CWE-189
CAPEC-92
Affected products
Libxml ≤ 1.8.16Libxml
CVSS vector
AV:N/AC:H/Au:N/C:P/I:P/A:P
Timeline
2011-01-01
Published
2011-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.237 · p96
Known exploited (KEV)
No
Known exploits — Сканер-ВС
35810
exploitdb · https://www.exploit-db.com/exploits/35810
Enterprise
Affected software
ProductVendorStatus
libxml2Tracked
libxml2Tracked
libxml2Tracked
libxml2Tracked
mingw32-libxml2Tracked
libxml*Tracked
libxml2*Tracked
libxml2*Tracked