← All CVEs

CVE-2016-4447

high · 7.5

The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.

7.5
CVSS
14.0%
EPSS (exploit prob.)
96th
EPSS percentile
2016-06-09
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
hpicewall_federation_agent3.0
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux15.10
canonicalubuntu_linux16.04
debiandebian_linux7.0
debiandebian_linux8.0
oraclevm_server3.3
oraclevm_server3.4
appleitunes12.4.1
microsoftwindowsall versions
appleiphone_os<= 9.3.2
applemac_os_x<= 10.11.5
appletvos<= 9.2.1
applewatchos<= 2.2.1
xmlsoftlibxml2<= 2.9.3
mcafeeweb_gateway>= 7.5.0.0, <= 7.5.2.10
mcafeeweb_gateway>= 7.6.0.0, <= 7.6.2.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-4447