Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid character in an XML document.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xerces-c | May 16, 2016 | May 13, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jul 18, 2016 |
| Freebsd | — | Upgrade xerces-c3 | Dec 10, 2025 | Jul 26, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/xerces-c. | Oct 30, 2017 | May 13, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 9, 2016 |
| Suse | — | Upgrade libxerces-c-3_2Upgrade libxerces-c-3_1-32bitUpgrade libxerces-c-3_1Upgrade libXerces-c-devel | Jul 26, 2016 | May 13, 2016 |
| Ubuntu | — | Upgrade libxerces-c-dev (Ubuntu Pro)Upgrade libxerces-c3.2 (Ubuntu Pro)Upgrade libxerces-c3.1 (Ubuntu Pro)Upgrade libxerces-c-doc (Ubuntu Pro)Upgrade libxerces-c-samples (Ubuntu Pro) | Mar 22, 2023 | May 13, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub