Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libxml2 | Jul 30, 2024 | Mar 15, 2004 |
| Freebsd | — | Upgrade libxml2 | Dec 10, 2025 | Feb 25, 2004 |
| Suse | — | Upgrade libxml2-develUpgrade libxml-x86Upgrade libxml-32bitUpgrade libxmlUpgrade libxml2-64bitUpgrade libxml2-x86Upgrade libxml-develUpgrade libxml2Upgrade libxml2-32bitUpgrade libxml-64bit | Feb 17, 2015 | Mar 15, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub