6.5

CVE-2009-2416

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.

Data is provided by the National Vulnerability Database (NVD)
XmlsoftLibxml Version1.8.17
XmlsoftLibxml2 Version2.5.10
XmlsoftLibxml2 Version2.6.16
XmlsoftLibxml2 Version2.6.26
XmlsoftLibxml2 Version2.6.27
XmlsoftLibxml2 Version2.6.32
FedoraprojectFedora Version10
FedoraprojectFedora Version11
DebianDebian Linux Version4.0
RedhatEnterprise Linux Version3.0
RedhatEnterprise Linux Version4.0
RedhatEnterprise Linux Version5.0
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version8.10
CanonicalUbuntu Linux Version9.04
GoogleChrome Version < 2.0.172.43
AppleSafari Version < 4.0.4
AppleiPhone OS Version >= 2.0 < 4.0
ApplemacOS X Version < 10.4.11
ApplemacOS X Version >= 10.5.0 < 10.5.8
ApplemacOS X Version >= 10.6.0 < 10.6.2
ApplemacOS X Server Version < 10.4.11
ApplemacOS X Server Version >= 10.5.0 < 10.5.8
ApplemacOS X Server Version >= 10.6.0 < 10.6.2
OpensuseOpensuse Version >= 10.3 <= 11.1
SuseLinux Enterprise Version10.0 Update-
SuseLinux Enterprise Version11.0 Update-
VMwareVcenter Server Version4.0 Update-
VMwareVma Version4.0
VMwareEsx Version3.0.3
VMwareEsx Version3.5
VMwareEsx Version4.0
VMwareESXi Version3.5
VMwareESXi Version4.0
SunOpenoffice.Org Version >= 2.0.0 < 2.4.3
SunOpenoffice.Org Version >= 3.0.0 < 3.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.19% 0.414
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

http://www.securityfocus.com/archive/1/507985/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/36010
Third Party Advisory
Broken Link
VDB Entry