CVE-2016-3627
—CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
Modified
Description
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document.
- Vendors
- opensusedebianhpxmlsoftcanonicalredhatoracle
- Products
- leap, debian linux, icewall federation agent, icewall file manager, libxml2, ubuntu linux, jboss core services, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux workstation
- Weakness
- CWE-674
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.