CVE-2006-10002 describes a heap corruption vulnerability in XML::Parser for Perl, affecting versions through 2.45. This flaw stems from a buffer overflow in the :utf8 PerlIO layer when processing XML input, leading to double-free conditions and application crashes. With a CVSS score of 7.5 (HIGH), this vulnerability has a network attack vector and low attack complexity, primarily impacting system availability by causing denial-of-service. There is no evidence of active exploitation, nor is public exploit code available on common platforms like Metasploit or ExploitDB. Community discussion and media coverage for this older vulnerability are minimal, indicating low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.48CPE matchmatch criteria | cpe:2.3:a:toddr:xml\:\:parser:*:*:*:*:*:perl:*:* | ||
>= 0, <= 2.45CPE match | cpe:2.3:a:toddr:xml\:\:parser:*:*:*:*:*:perl:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.