CVE-2009-2416
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
- Affected products
- Red Hat, Vmware Vcenter, Libxml, Libxml2
- Xmlsoft Libxml
- = 1.8.17
- Xmlsoft libxml2
- = 2.5.10, 2.6.16, 2.6.26, 2.6.27, 2.6.32
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 1.8% (77th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2009-08-11
CVE-2009-2416 at NVD
2 known exploits for CVE-2009-2416
Proof-of-concept code and exploit modules indexed by Sploitus