The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed HTML comment.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libxml2Upgrade libxml2-staticUpgrade libxml2-develUpgrade libxml2-debuginfoUpgrade libxml2-python | Apr 27, 2020 | Apr 11, 2016 |
| Debian | — | Upgrade libxml2 | Jan 19, 2016 | Dec 23, 2015 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jul 20, 2017 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.3.0.0.30.0 on Solaris 11.3 | Jun 18, 2018 | Apr 11, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 19, 2015 |
| Suse | — | Upgrade libxml2-2-32bitUpgrade libxml2-32bitUpgrade sles12-docker-imageUpgrade libxml2-2Upgrade libxml2-toolsUpgrade libxml2-devel-32bitUpgrade libxml2-docUpgrade libxml2-x86Upgrade libxml2Upgrade libxml2-pythonUpgrade python-libxml2Upgrade libxml2-devel | Feb 2, 2016 | Jan 20, 2016 |
| Ubuntu | — | Upgrade libxml2 | Feb 2, 2016 | Jan 19, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub