CyberSec.Space Logo
Back to CVE Browser

CVE-2008-3529

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0740%
EPSS Percentile8.94th
PublishedSep 12, 2008
Last ModifiedApr 23, 2026

Vulnerability Description

Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.

Affected Platforms (CPE)

πŸ“¦
Xmlsoft

Libxml2

< 2.7.0
πŸ’»
Debian

Debian Linux

= 4.0
πŸ’»
Canonical

Ubuntu Linux

= 6.06
πŸ’»
Canonical

Ubuntu Linux

= 6.06
πŸ’»
Canonical

Ubuntu Linux

= 7.04
πŸ’»
Canonical

Ubuntu Linux

= 7.10
πŸ’»
Canonical

Ubuntu Linux

= 8.04
πŸ’»
Canonical

Ubuntu Linux

= 8.04
πŸ’»
Canonical

Ubuntu Linux

= 8.10
πŸ’»
Canonical

Ubuntu Linux

= 9.04
πŸ“¦
Apple

Safari

< 4.0
πŸ“¦
Apple

Safari

>= 3.2.0 and < 3.2.3
πŸ’»
Apple

Iphone Os

< 3.0
πŸ’»
Apple

Mac Os X

< 10.5.7
πŸ’»
Apple

Mac Os X

= 10.5.7

References & Advisories

Related Vulnerabilities