CVE-2008-3281
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
- Xmlsoft libxml2
- ≤ 2.6.32
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 2.5% (84th percentile)
- Weakness
- CWE-776
- NVD status
- Modified
- Published
- 2008-08-27
CVE-2008-3281 at NVD
1 known exploit for CVE-2008-3281
Proof-of-concept code and exploit modules indexed by Sploitus