Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-3529

54
FAUCET Score

CVE-2008-3529 is a critical heap-based buffer overflow vulnerability in the libxml2 library, specifically within the xmlParseAttValueComplex function, affecting versions prior to 2.7.0. This flaw impacts products from Apple, Canonical, Debian, and xmlsoft. With a CVSS score of 10.0, it allows unauthenticated, remote attackers to cause a denial of service or execute arbitrary code with low attack complexity. While not listed on CISA's KEV catalog, a proof-of-concept exploit exists on ExploitDB, demonstrating its potential for exploitation, though there is no evidence of widespread active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.7.0CPE matchmatch criteria
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
7.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

10.0HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
23.37%
Probability of exploitation in next 30 days
EPSS Percentile
97.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-8798 · May 26, 2009
This CVE's current EPSS score of 0.2337 is in the 96th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: libxml2-0:2.4.19-11.ent
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: libxml2-0:2.5.10-13
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: libxml2-0:2.6.16-12.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: libxml2-0:2.6.26-2.1.2.6
View patch

Vendor Advisories (1)

redhatCVE-2008-3529Important

libxml2: long entity name heap buffer overflow

Sep 11, 2008

References

lists.apple.com / archives/security-announce/2009/jun/msg00002.html
Broken LinkMailing List
lists.apple.com / archives/security-announce/2009/Jun/msg00005.html
Mailing ListThird Party Advisory
lists.apple.com / archives/security-announce/2009/May/msg00000.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2008-09/msg00004.html
Mailing ListThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
secunia.com / advisories/31558
Third Party Advisory
secunia.com / advisories/31855
Third Party Advisory
secunia.com / advisories/31860
Third Party Advisory
secunia.com / advisories/31868
Third Party Advisory
secunia.com / advisories/31982
Third Party Advisory
secunia.com / advisories/32265
Third Party Advisory
secunia.com / advisories/32280
Third Party Advisory
secunia.com / advisories/32807
Third Party Advisory
secunia.com / advisories/32974
Third Party Advisory
secunia.com / advisories/33715
Third Party Advisory
secunia.com / advisories/33722
Third Party Advisory
secunia.com / advisories/35056
Third Party Advisory
secunia.com / advisories/35074
Third Party Advisory
secunia.com / advisories/35379
Third Party Advisory
secunia.com / advisories/36173
Third Party Advisory
secunia.com / advisories/36235
Third Party Advisory
security.gentoo.org / glsa/glsa-200812-06.xml
Third Party Advisory
securitytracker.com / id
Third Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/45085
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11760
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6103
Third Party Advisory
sunsolve.sun.com / search/document.do
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
support.apple.com / kb/HT3549
Third Party Advisory
support.apple.com / kb/HT3550
Third Party Advisory
support.apple.com / kb/HT3613
Third Party Advisory
support.apple.com / kb/HT3639
Third Party Advisory
support.avaya.com / elmodocs2/security/ASA-2008-400.htm
Third Party Advisory
support.avaya.com / elmodocs2/security/ASA-2009-025.htm
Third Party Advisory
usn.ubuntu.com / 644-1
Third Party Advisory
exploit-db.com / exploits/8798
ExploitThird Party AdvisoryVDB Entry
wiki.rpath.com / Advisories:rPSA-2008-0325
Broken Link
debian.org / security/2008/dsa-1654
Third Party Advisory
mandriva.com / security/advisories
Broken Link
redhat.com / support/errata/RHSA-2008-0884.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0886.html
Third Party Advisory
securityfocus.com / bid/31126
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-815-1
Third Party Advisory
us-cert.gov / cas/techalerts/TA09-133A.html
Third Party AdvisoryUS Government Resource
vupen.com / english/advisories/2008/2822
Third Party Advisory
vupen.com / english/advisories/2009/1297
Third Party Advisory
vupen.com / english/advisories/2009/1298
Third Party Advisory
vupen.com / english/advisories/2009/1522
Third Party Advisory
vupen.com / english/advisories/2009/1621
Third Party Advisory
xmlsoft.org / news.html
Release NotesVendor Advisory