Vulnerability Details CVE-2009-2416
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.6%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.3
Products affected by CVE-2009-2416
-
-
cpe:2.3:a:apple:safari:1.0
-
cpe:2.3:a:apple:safari:1.0.0
-
cpe:2.3:a:apple:safari:1.0.0b1
-
cpe:2.3:a:apple:safari:1.0.0b2
-
cpe:2.3:a:apple:safari:1.0.1
-
cpe:2.3:a:apple:safari:1.0.2
-
cpe:2.3:a:apple:safari:1.0.3
-
cpe:2.3:a:apple:safari:1.0b1
-
cpe:2.3:a:apple:safari:1.1
-
cpe:2.3:a:apple:safari:1.1.0
-
cpe:2.3:a:apple:safari:1.1.1
-
cpe:2.3:a:apple:safari:1.2
-
cpe:2.3:a:apple:safari:1.2.0
-
cpe:2.3:a:apple:safari:1.2.1
-
cpe:2.3:a:apple:safari:1.2.2
-
cpe:2.3:a:apple:safari:1.2.3
-
cpe:2.3:a:apple:safari:1.2.4
-
cpe:2.3:a:apple:safari:1.2.5
-
cpe:2.3:a:apple:safari:1.3
-
cpe:2.3:a:apple:safari:1.3.0
-
cpe:2.3:a:apple:safari:1.3.1
-
cpe:2.3:a:apple:safari:1.3.2
-
-
cpe:2.3:a:apple:safari:2.0
-
cpe:2.3:a:apple:safari:2.0.0
-
cpe:2.3:a:apple:safari:2.0.1
-
cpe:2.3:a:apple:safari:2.0.2
-
cpe:2.3:a:apple:safari:2.0.3
-
cpe:2.3:a:apple:safari:2.0.4
-
-
cpe:2.3:a:apple:safari:3.0
-
cpe:2.3:a:apple:safari:3.0.0
-
cpe:2.3:a:apple:safari:3.0.0b
-
cpe:2.3:a:apple:safari:3.0.1
-
cpe:2.3:a:apple:safari:3.0.1b
-
cpe:2.3:a:apple:safari:3.0.2
-
cpe:2.3:a:apple:safari:3.0.2b
-
cpe:2.3:a:apple:safari:3.0.3
-
cpe:2.3:a:apple:safari:3.0.3b
-
cpe:2.3:a:apple:safari:3.0.4
-
cpe:2.3:a:apple:safari:3.0.4b
-
cpe:2.3:a:apple:safari:3.0.5
-
cpe:2.3:a:apple:safari:3.1.0
-
cpe:2.3:a:apple:safari:3.1.0b
-
cpe:2.3:a:apple:safari:3.1.1
-
cpe:2.3:a:apple:safari:3.1.1b
-
cpe:2.3:a:apple:safari:3.1.2
-
cpe:2.3:a:apple:safari:3.1.2b
-
cpe:2.3:a:apple:safari:3.2.0
-
cpe:2.3:a:apple:safari:3.2.0b
-
cpe:2.3:a:apple:safari:3.2.1
-
cpe:2.3:a:apple:safari:3.2.1b
-
cpe:2.3:a:apple:safari:3.2.2
-
cpe:2.3:a:apple:safari:3.2.2b
-
cpe:2.3:a:apple:safari:4.0
-
cpe:2.3:a:apple:safari:4.0.0b
-
cpe:2.3:a:apple:safari:4.0.1
-
cpe:2.3:a:apple:safari:4.0.2
-
cpe:2.3:a:apple:safari:4.0.3
-
cpe:2.3:a:google:chrome:-
-
cpe:2.3:a:google:chrome:0.1.38.1
-
cpe:2.3:a:google:chrome:0.1.38.2
-
cpe:2.3:a:google:chrome:0.1.38.4
-
cpe:2.3:a:google:chrome:0.1.40.1
-
cpe:2.3:a:google:chrome:0.1.42.2
-
cpe:2.3:a:google:chrome:0.1.42.3
-
cpe:2.3:a:google:chrome:0.2.149.27
-
cpe:2.3:a:google:chrome:0.2.149.29
-
cpe:2.3:a:google:chrome:0.2.149.30
-
cpe:2.3:a:google:chrome:0.2.152.1
-
cpe:2.3:a:google:chrome:0.2.153.1
-
cpe:2.3:a:google:chrome:0.3.154.0
-
cpe:2.3:a:google:chrome:0.3.154.3
-
cpe:2.3:a:google:chrome:0.4.154.18
-
cpe:2.3:a:google:chrome:0.4.154.22
-
cpe:2.3:a:google:chrome:0.4.154.31
-
cpe:2.3:a:google:chrome:0.4.154.33
-
cpe:2.3:a:google:chrome:1.0.154.36
-
cpe:2.3:a:google:chrome:1.0.154.39
-
cpe:2.3:a:google:chrome:1.0.154.42
-
cpe:2.3:a:google:chrome:1.0.154.43
-
cpe:2.3:a:google:chrome:1.0.154.46
-
cpe:2.3:a:google:chrome:1.0.154.48
-
cpe:2.3:a:google:chrome:1.0.154.52
-
cpe:2.3:a:google:chrome:1.0.154.53
-
cpe:2.3:a:google:chrome:1.0.154.59
-
cpe:2.3:a:google:chrome:1.0.154.64
-
cpe:2.3:a:google:chrome:1.0.154.65
-
cpe:2.3:a:google:chrome:2.0.156.1
-
cpe:2.3:a:google:chrome:2.0.157.0
-
cpe:2.3:a:google:chrome:2.0.157.2
-
cpe:2.3:a:google:chrome:2.0.158.0
-
cpe:2.3:a:google:chrome:2.0.159.0
-
cpe:2.3:a:google:chrome:2.0.169.0
-
cpe:2.3:a:google:chrome:2.0.169.1
-
cpe:2.3:a:google:chrome:2.0.170.0
-
cpe:2.3:a:google:chrome:2.0.172
-
cpe:2.3:a:google:chrome:2.0.172.2
-
cpe:2.3:a:google:chrome:2.0.172.27
-
cpe:2.3:a:google:chrome:2.0.172.28
-
cpe:2.3:a:google:chrome:2.0.172.30
-
cpe:2.3:a:google:chrome:2.0.172.31
-
cpe:2.3:a:google:chrome:2.0.172.33
-
cpe:2.3:a:google:chrome:2.0.172.37
-
cpe:2.3:a:google:chrome:2.0.172.38
-
cpe:2.3:a:google:chrome:2.0.172.8
-
cpe:2.3:a:sun:openoffice.org:2.0.0
-
cpe:2.3:a:sun:openoffice.org:2.1.0
-
cpe:2.3:a:sun:openoffice.org:2.2.0
-
cpe:2.3:a:sun:openoffice.org:2.3.0
-
cpe:2.3:a:sun:openoffice.org:2.4.0
-
cpe:2.3:a:sun:openoffice.org:2.4.1
-
cpe:2.3:a:sun:openoffice.org:2.4.2
-
cpe:2.3:a:sun:openoffice.org:3.0.0
-
cpe:2.3:a:sun:openoffice.org:3.0.1
-
cpe:2.3:a:sun:openoffice.org:3.1.0
-
cpe:2.3:a:vmware:vcenter_server:4.0
-
-
cpe:2.3:a:xmlsoft:libxml2:2.5.10
-
cpe:2.3:a:xmlsoft:libxml2:2.6.16
-
cpe:2.3:a:xmlsoft:libxml2:2.6.26
-
cpe:2.3:a:xmlsoft:libxml2:2.6.27
-
cpe:2.3:a:xmlsoft:libxml2:2.6.32
-
cpe:2.3:a:xmlsoft:libxml:1.8.17
-
cpe:2.3:o:apple:iphone_os:2.0
-
cpe:2.3:o:apple:iphone_os:2.0.0
-
cpe:2.3:o:apple:iphone_os:2.0.1
-
cpe:2.3:o:apple:iphone_os:2.0.2
-
cpe:2.3:o:apple:iphone_os:2.1
-
cpe:2.3:o:apple:iphone_os:2.1.1
-
cpe:2.3:o:apple:iphone_os:2.2
-
cpe:2.3:o:apple:iphone_os:2.2.1
-
cpe:2.3:o:apple:iphone_os:3.0
-
cpe:2.3:o:apple:iphone_os:3.0.1
-
cpe:2.3:o:apple:iphone_os:3.1
-
cpe:2.3:o:apple:iphone_os:3.1.1
-
cpe:2.3:o:apple:iphone_os:3.1.2
-
cpe:2.3:o:apple:iphone_os:3.1.3
-
cpe:2.3:o:apple:iphone_os:3.2
-
cpe:2.3:o:apple:iphone_os:3.2.1
-
cpe:2.3:o:apple:iphone_os:3.2.2
-
cpe:2.3:o:apple:mac_os_x:-
-
cpe:2.3:o:apple:mac_os_x:10.0
-
cpe:2.3:o:apple:mac_os_x:10.0.0
-
cpe:2.3:o:apple:mac_os_x:10.0.1
-
cpe:2.3:o:apple:mac_os_x:10.0.2
-
cpe:2.3:o:apple:mac_os_x:10.0.3
-
cpe:2.3:o:apple:mac_os_x:10.0.4
-
cpe:2.3:o:apple:mac_os_x:10.1
-
cpe:2.3:o:apple:mac_os_x:10.1.0
-
cpe:2.3:o:apple:mac_os_x:10.1.1
-
cpe:2.3:o:apple:mac_os_x:10.1.2
-
cpe:2.3:o:apple:mac_os_x:10.1.3
-
cpe:2.3:o:apple:mac_os_x:10.1.4
-
cpe:2.3:o:apple:mac_os_x:10.1.5
-
cpe:2.3:o:apple:mac_os_x:10.2
-
cpe:2.3:o:apple:mac_os_x:10.2.0
-
cpe:2.3:o:apple:mac_os_x:10.2.1
-
cpe:2.3:o:apple:mac_os_x:10.2.2
-
cpe:2.3:o:apple:mac_os_x:10.2.3
-
cpe:2.3:o:apple:mac_os_x:10.2.4
-
cpe:2.3:o:apple:mac_os_x:10.2.5
-
cpe:2.3:o:apple:mac_os_x:10.2.6
-
cpe:2.3:o:apple:mac_os_x:10.2.7
-
cpe:2.3:o:apple:mac_os_x:10.2.8
-
cpe:2.3:o:apple:mac_os_x:10.3
-
cpe:2.3:o:apple:mac_os_x:10.3.0
-
cpe:2.3:o:apple:mac_os_x:10.3.1
-
cpe:2.3:o:apple:mac_os_x:10.3.2
-
cpe:2.3:o:apple:mac_os_x:10.3.3
-
cpe:2.3:o:apple:mac_os_x:10.3.4
-
cpe:2.3:o:apple:mac_os_x:10.3.5
-
cpe:2.3:o:apple:mac_os_x:10.3.6
-
cpe:2.3:o:apple:mac_os_x:10.3.7
-
cpe:2.3:o:apple:mac_os_x:10.3.8
-
cpe:2.3:o:apple:mac_os_x:10.3.9
-
cpe:2.3:o:apple:mac_os_x:10.4
-
cpe:2.3:o:apple:mac_os_x:10.4.0
-
cpe:2.3:o:apple:mac_os_x:10.4.1
-
cpe:2.3:o:apple:mac_os_x:10.4.10
-
cpe:2.3:o:apple:mac_os_x:10.4.2
-
cpe:2.3:o:apple:mac_os_x:10.4.3
-
cpe:2.3:o:apple:mac_os_x:10.4.4
-
cpe:2.3:o:apple:mac_os_x:10.4.5
-
cpe:2.3:o:apple:mac_os_x:10.4.6
-
cpe:2.3:o:apple:mac_os_x:10.4.7
-
cpe:2.3:o:apple:mac_os_x:10.4.8
-
cpe:2.3:o:apple:mac_os_x:10.4.9
-
cpe:2.3:o:apple:mac_os_x:10.5.0
-
cpe:2.3:o:apple:mac_os_x:10.5.1
-
cpe:2.3:o:apple:mac_os_x:10.5.2
-
cpe:2.3:o:apple:mac_os_x:10.5.3
-
cpe:2.3:o:apple:mac_os_x:10.5.4
-
cpe:2.3:o:apple:mac_os_x:10.5.5
-
cpe:2.3:o:apple:mac_os_x:10.5.6
-
cpe:2.3:o:apple:mac_os_x:10.5.7
-
cpe:2.3:o:apple:mac_os_x:10.6.0
-
cpe:2.3:o:apple:mac_os_x:10.6.1
-
cpe:2.3:o:apple:mac_os_x_server:-
-
cpe:2.3:o:apple:mac_os_x_server:10.0
-
cpe:2.3:o:apple:mac_os_x_server:10.0.0
-
cpe:2.3:o:apple:mac_os_x_server:10.0.1
-
cpe:2.3:o:apple:mac_os_x_server:10.0.2
-
cpe:2.3:o:apple:mac_os_x_server:10.0.3
-
cpe:2.3:o:apple:mac_os_x_server:10.0.4
-
cpe:2.3:o:apple:mac_os_x_server:10.1
-
cpe:2.3:o:apple:mac_os_x_server:10.1.0
-
cpe:2.3:o:apple:mac_os_x_server:10.1.1
-
cpe:2.3:o:apple:mac_os_x_server:10.1.2
-
cpe:2.3:o:apple:mac_os_x_server:10.1.3
-
cpe:2.3:o:apple:mac_os_x_server:10.1.4
-
cpe:2.3:o:apple:mac_os_x_server:10.1.5
-
cpe:2.3:o:apple:mac_os_x_server:10.2
-
cpe:2.3:o:apple:mac_os_x_server:10.2.0
-
cpe:2.3:o:apple:mac_os_x_server:10.2.1
-
cpe:2.3:o:apple:mac_os_x_server:10.2.2
-
cpe:2.3:o:apple:mac_os_x_server:10.2.3
-
cpe:2.3:o:apple:mac_os_x_server:10.2.4
-
cpe:2.3:o:apple:mac_os_x_server:10.2.5
-
cpe:2.3:o:apple:mac_os_x_server:10.2.6
-
cpe:2.3:o:apple:mac_os_x_server:10.2.7
-
cpe:2.3:o:apple:mac_os_x_server:10.2.8
-
cpe:2.3:o:apple:mac_os_x_server:10.3
-
cpe:2.3:o:apple:mac_os_x_server:10.3.0
-
cpe:2.3:o:apple:mac_os_x_server:10.3.1
-
cpe:2.3:o:apple:mac_os_x_server:10.3.2
-
cpe:2.3:o:apple:mac_os_x_server:10.3.3
-
cpe:2.3:o:apple:mac_os_x_server:10.3.4
-
cpe:2.3:o:apple:mac_os_x_server:10.3.5
-
cpe:2.3:o:apple:mac_os_x_server:10.3.6
-
cpe:2.3:o:apple:mac_os_x_server:10.3.7
-
cpe:2.3:o:apple:mac_os_x_server:10.3.8
-
cpe:2.3:o:apple:mac_os_x_server:10.3.9
-
cpe:2.3:o:apple:mac_os_x_server:10.4
-
cpe:2.3:o:apple:mac_os_x_server:10.4.0
-
cpe:2.3:o:apple:mac_os_x_server:10.4.1
-
cpe:2.3:o:apple:mac_os_x_server:10.4.10
-
cpe:2.3:o:apple:mac_os_x_server:10.4.2
-
cpe:2.3:o:apple:mac_os_x_server:10.4.3
-
cpe:2.3:o:apple:mac_os_x_server:10.4.4
-
cpe:2.3:o:apple:mac_os_x_server:10.4.5
-
cpe:2.3:o:apple:mac_os_x_server:10.4.6
-
cpe:2.3:o:apple:mac_os_x_server:10.4.7
-
cpe:2.3:o:apple:mac_os_x_server:10.4.8
-
cpe:2.3:o:apple:mac_os_x_server:10.4.9
-
cpe:2.3:o:apple:mac_os_x_server:10.5.0
-
cpe:2.3:o:apple:mac_os_x_server:10.5.1
-
cpe:2.3:o:apple:mac_os_x_server:10.5.2
-
cpe:2.3:o:apple:mac_os_x_server:10.5.3
-
cpe:2.3:o:apple:mac_os_x_server:10.5.4
-
cpe:2.3:o:apple:mac_os_x_server:10.5.5
-
cpe:2.3:o:apple:mac_os_x_server:10.5.6
-
cpe:2.3:o:apple:mac_os_x_server:10.5.7
-
cpe:2.3:o:apple:mac_os_x_server:10.6.0
-
cpe:2.3:o:apple:mac_os_x_server:10.6.1
-
cpe:2.3:o:apple:mac_os_x_server:5.0.14
-
cpe:2.3:o:apple:mac_os_x_server:5.0.15
-
cpe:2.3:o:apple:mac_os_x_server:5.0.2
-
cpe:2.3:o:apple:mac_os_x_server:5.0.3
-
cpe:2.3:o:canonical:ubuntu_linux:6.06
-
cpe:2.3:o:canonical:ubuntu_linux:8.04
-
cpe:2.3:o:canonical:ubuntu_linux:8.10
-
cpe:2.3:o:canonical:ubuntu_linux:9.04
-
cpe:2.3:o:debian:debian_linux:4.0
-
cpe:2.3:o:fedoraproject:fedora:10
-
cpe:2.3:o:fedoraproject:fedora:11
-
cpe:2.3:o:opensuse:opensuse:10.3
-
cpe:2.3:o:opensuse:opensuse:10.3-11.1
-
cpe:2.3:o:opensuse:opensuse:11.0
-
cpe:2.3:o:opensuse:opensuse:11.1
-
cpe:2.3:o:redhat:enterprise_linux:3.0
-
cpe:2.3:o:redhat:enterprise_linux:4.0
-
cpe:2.3:o:redhat:enterprise_linux:5.0
-
cpe:2.3:o:suse:linux_enterprise:10.0
-
cpe:2.3:o:suse:linux_enterprise:11.0
-
cpe:2.3:o:suse:linux_enterprise_server:9
-
cpe:2.3:o:vmware:esx:3.0.3
-
-
-
cpe:2.3:o:vmware:esxi:3.5
-
cpe:2.3:o:vmware:esxi:4.0