CVE-2006-10003 identifies an off-by-one heap buffer overflow in XML::Parser versions through 2.47 for Perl, specifically affecting the st_serial_stack function when parsing XML files with very deep element nesting. This critical vulnerability, rated 9.8 CVSS, is network-exploitable with low attack complexity and no user interaction, potentially leading to full compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code available, the issue has received community discussion and media coverage, prompting security updates from vendors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.48CPE matchmatch criteria | cpe:2.3:a:toddr:xml\:\:parser:*:*:*:*:*:perl:*:* | ||
>= 0, <= 2.47CPE match | cpe:2.3:a:toddr:xml\:\:parser:*:*:*:*:*:perl:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.