Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-2414

Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 76.5%
CVSS Severity
CVSS v2 Score 4.3
References
Products affected by CVE-2009-2414
  • Xmlsoft » Libxml2 » Version: 2.5.10
    cpe:2.3:a:xmlsoft:libxml2:2.5.10
  • Xmlsoft » Libxml2 » Version: 2.6.16
    cpe:2.3:a:xmlsoft:libxml2:2.6.16
  • Xmlsoft » Libxml2 » Version: 2.6.26
    cpe:2.3:a:xmlsoft:libxml2:2.6.26
  • Xmlsoft » Libxml2 » Version: 2.6.27
    cpe:2.3:a:xmlsoft:libxml2:2.6.27
  • Xmlsoft » Libxml2 » Version: 2.6.32
    cpe:2.3:a:xmlsoft:libxml2:2.6.32
  • Xmlsoft » Libxml » Version: 1.8.17
    cpe:2.3:a:xmlsoft:libxml:1.8.17


Contact Us

Shodan ® - All rights reserved