← Back

CVE-2021-3517

nvd nist
Published: May 19, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Exploitability: 3.9 / Impact: 4.7
Source: NVD

Description

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.

Affected (33)

Show all products
1 product
Libxml2
2 products
Enterprise Linux
Jboss Core Services
1 product
Fedora
1 product
Debian Linux
16 products
Active Iq Unified Manager
Clustered Data Ontap
E Series Santricity Os Controller
E Series Santricity Web Services
Hci Management Node
Oncommand Insight
Oncommand Workflow Automation
Santricity Unified Manager
Snapdrive
Snapmanager
Solidfire
Hci H410c Firmware
7 products
Enterprise Manager Base Platform
Mysql Workbench
Openjdk
Peoplesoft Enterprise Peopletools
Real User Experience Insight
Zfs Storage Appliance Kit
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.9.11
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
All versions
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration E
17 vulnerable
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Hci H410c
All versions
Configuration G
9 vulnerable

References (26)

Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
Not Applicable
Source: secalert@redhat.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.