← All CVEs

CVE-2008-3529

high · 10

Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.

10
CVSS
23.4%
EPSS (exploit prob.)
98th
EPSS percentile
2008-09-12
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
xmlsoftlibxml2< 2.7.0
debiandebian_linux4.0
canonicalubuntu_linux6.06
canonicalubuntu_linux6.06
canonicalubuntu_linux7.04
canonicalubuntu_linux7.10
canonicalubuntu_linux8.04
canonicalubuntu_linux8.04
canonicalubuntu_linux8.10
canonicalubuntu_linux9.04
applesafari< 4.0
applesafari>= 3.2.0, < 3.2.3
appleiphone_os< 3.0
applemac_os_x< 10.5.7
applemac_os_x10.5.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-3529