← All CVEs

CVE-2021-3517

high · 8.6

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.

8.6
CVSS
17.0%
EPSS (exploit prob.)
97th
EPSS percentile
2021-05-19
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Weaknesses

CWE-787CWE-125

Affected products

VendorProductAffected versions
xmlsoftlibxml2< 2.9.11
redhatjboss_core_servicesall versions
redhatenterprise_linux8.0
fedoraprojectfedora33
fedoraprojectfedora34
debiandebian_linux9.0
netappactive_iq_unified_managerall versions
netappactive_iq_unified_managerall versions
netappclustered_data_ontapall versions
netappclustered_data_ontap_antivirus_connectorall versions
netappe-series_santricity_os_controller>= 11.0.0, <= 11.70.1
netappe-series_santricity_storage_managerall versions
netappe-series_santricity_web_servicesall versions
netapphci_management_nodeall versions
netappmanageability_software_development_kitall versions
netapponcommand_insightall versions
netapponcommand_workflow_automationall versions
netappontap_select_deploy_administration_utilityall versions
netappsantricity_unified_managerall versions
netappsnapdriveall versions
netappsnapmanagerall versions
netappsnapmanagerall versions
netappsolidfireall versions
netapphci_h410c_firmwareall versions
netapphci_h410call versions
oraclecommunications_cloud_native_core_network_function_cloud_native_environment1.10.0
oracleenterprise_manager_base_platform13.4.0.0
oracleenterprise_manager_base_platform13.5.0.0
oraclemysql_workbench<= 8.0.26
oracleopenjdk8
oraclepeoplesoft_enterprise_peopletools8.58
oraclereal_user_experience_insight13.4.1.0
oraclereal_user_experience_insight13.5.1.0
oraclezfs_storage_appliance_kit8.8

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-3517