ZeroHour

CVE-2021-3537

CVSS 3.1
5.9 medium
EPSS
4%p88
Published
()
Modified
Description

A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.

Vendors
xmlsoftredhatdebianfedoraprojectnetapporacle
Products
libxml2, jboss core services, enterprise linux, debian linux, fedora, active iq unified manager, clustered data ontap, clustered data ontap antivirus connector, manageability software development kit, ontap select deploy administration utility, snapdrive, hci h410c firmware
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.