← All CVEs

CVE-2021-3518

high · 8.8

There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.

8.8
CVSS
21.9%
EPSS (exploit prob.)
98th
EPSS percentile
2021-05-18
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-416

Affected products

VendorProductAffected versions
xmlsoftlibxml2< 2.9.11
debiandebian_linux9.0
redhatjboss_core_servicesall versions
redhatenterprise_linux8.0
fedoraprojectfedora33
fedoraprojectfedora34
netappactive_iq_unified_managerall versions
netappclustered_data_ontapall versions
netappclustered_data_ontap_antivirus_connectorall versions
netappmanageability_software_development_kitall versions
netappontap_select_deploy_administration_utilityall versions
netappsnapdriveall versions
netapphci_h410c_firmwareall versions
netapphci_h410call versions
oraclecommunications_cloud_native_core_network_function_cloud_native_environment1.10.0
oracleenterprise_manager_base_platform13.4.0.0
oracleenterprise_manager_base_platform13.5.0.0
oracleenterprise_manager_ops_center12.4.0.0
oraclemysql_workbench<= 8.0.26
oraclepeoplesoft_enterprise_peopletools8.58
oraclereal_user_experience_insight13.4.1.0
oraclereal_user_experience_insight13.5.1.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-3518