ZeroHour

CVE-2021-3516

PoC
CVSS 3.1
7.8 high
EPSS
2%p80
Published
()
Modified
Description

There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.

Vendors
xmlsoftdebianfedoraprojectredhatnetapporacle
Products
xmllint, debian linux, fedora, jboss core services, enterprise linux, clustered data ontap, clustered data ontap antivirus connector, ontap select deploy administration utility, zfs storage appliance kit
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.