← Back

CVE-2009-2416

nvd nist
Published: Aug 11, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.

Affected (38)

Show all products
2 products
Libxml
Libxml2
1 product
Fedora
1 product
Debian Linux
1 product
Enterprise Linux
1 product
Ubuntu Linux
1 product
Chrome
4 products
Iphone Os
Mac Os X
Mac Os X Server
Safari
1 product
Opensuse
2 products
Linux Enterprise
Linux Enterprise Server
4 products
Esx
Esxi
Vcenter Server
Vma
1 product
Openoffice.org
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.8.17
Xmlsoft
Version 2.5.10
Version 2.6.16
Version 2.6.26
Version 2.6.27
Version 2.6.32
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 10
Version 11
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 3.0
Version 4.0
Version 5.0
Configuration E
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 6.06
Version 8.04
Version 8.10
Version 9.04
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.0.172.43
Configuration G
8 vulnerable
Vulnerable SoftwareAffected Versions
From 2.0 to 4.0
Apple
Before 10.4.11
From 10.5.0 to 10.5.8
From 10.6.0 to 10.6.2
Apple
Before 10.4.11
From 10.5.0 to 10.5.8
From 10.6.0 to 10.6.2
Before 4.0.4
Configuration H
4 vulnerable
Vulnerable SoftwareAffected Versions
From 10.3 to 11.1
Suse
Version 10.0
Version 11.0
Version 9
Configuration I
7 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Version 3.0.3
Version 3.5
Version 4.0
Vmware
Version 3.5
Version 4.0
Version 4.0
Version 4.0
Configuration J
2 vulnerable
Vulnerable SoftwareAffected Versions
Sun
From 2.0.0 to 2.4.3
From 3.0.0 to 3.1.1

References (72)

Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Mailing ListPatch
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Broken LinkThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
Broken LinkThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List

Timeline

No history available yet.