Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Openoffice | — | Upgrade Apache OpenOffice to the latest version | Sep 12, 2025 | Aug 11, 2009 |
| Apple Osx Libxml | — | Upgrade macOS to the latest versionApply OS X security update 2009-006 | Dec 16, 2011 | Aug 11, 2009 |
| Apple Safari | — | Uninstall Apple Safari on WindowsUpgrade to Apple Safari version 4.0.4 | Jan 5, 2012 | Aug 11, 2009 |
| Centos_linux | — | Upgrade libxml-develUpgrade libxmlUpgrade libxml2-pythonUpgrade libxml2-develUpgrade libxml2 | Dec 1, 2016 | Aug 11, 2009 |
| Debian | — | Upgrade libxml2 | Jul 30, 2024 | Aug 11, 2009 |
| Freebsd | — | Upgrade libxml | Dec 10, 2025 | Nov 10, 2011 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2. | Oct 30, 2017 | Aug 11, 2009 |
| Oracle_linux | — | Upgrade libxml2-pythonUpgrade libxml2-develUpgrade libxml2 | Oct 16, 2024 | Aug 11, 2009 |
| Suse | — | Upgrade libxml2-devel-32bitUpgrade libxmlUpgrade libxml2-docUpgrade libxml2-develUpgrade libxml-32bitUpgrade libxml2-32bitUpgrade libxml-develUpgrade libxml2Upgrade libxml2-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libxml2 | Nov 8, 2024 | Aug 11, 2009 |
| Vmsa 2009 0016 5 Updated Service Console Package Libxml2 | — | Upgrade VMware ESX 4.0 to build number 208167Upgrade VMware ESX 3.5 to build number 226117 | Sep 2, 2010 | Aug 11, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub