V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2012-5134
ANC
MediumConfirmedExploit available

Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome befo…

CVSS
6.8
Medium
EPSS
0.02
p84
Published
2012-01-01
Updated
2012-01-01
Description

Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.

Tags · CWE
RCE
CWE-119
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-100
CAPEC-123
Affected products
Chrome ≤ 23.0.1271.89ChromeLibxml2 ≤ 2.9.0Libxml2
CVSS vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Timeline
2012-01-01
Published
2012-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.021 · p84
Known exploited (KEV)
No
Known exploits — Сканер-ВС
35810
exploitdb · https://www.exploit-db.com/exploits/35810
Enterprise
Affected software
ProductVendorStatus
Tracked
Tracked
Tracked
libxml2Tracked
libxml2Tracked
libxml2Tracked
libxml2Tracked
mingw32-libxml2Tracked
chrome*Tracked
iphone_os*Tracked
libxml2*Tracked