ZeroHour

CVE-2021-3518

CVSS 3.1
8.8 high
EPSS
4%p89
Published
()
Modified
Description

There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.

Vendors
xmlsoftdebianredhatfedoraprojectnetapporacle
Products
libxml2, debian linux, jboss core services, enterprise linux, fedora, active iq unified manager, clustered data ontap, clustered data ontap antivirus connector, manageability software development kit, ontap select deploy administration utility, snapdrive, hci h410c firmware
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.