Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-2414

19
FAUCET Score

CVE-2009-2414 describes a stack consumption vulnerability in libxml2 (versions 2.5.10, 2.6.16, 2.6.26, 2.6.27, 2.6.32) and libxml (version 1.8.17). This flaw allows remote attackers to trigger a denial of service (application crash) by submitting a specially crafted DTD with a large depth of element declarations, leading to excessive function recursion. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity and potential for partial availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
1.8.17CPE matchmatch criteria
cpe:2.3:a:xmlsoft:libxml:1.8.17:*:*:*:*:*:*:*
2.5.10CPE matchmatch criteria
cpe:2.3:a:xmlsoft:libxml2:2.5.10:*:*:*:*:*:*:*
2.6.16CPE matchmatch criteria
cpe:2.3:a:xmlsoft:libxml2:2.6.16:*:*:*:*:*:*:*
2.6.26CPE matchmatch criteria
cpe:2.3:a:xmlsoft:libxml2:2.6.26:*:*:*:*:*:*:*
2.6.27CPE matchmatch criteria
cpe:2.3:a:xmlsoft:libxml2:2.6.27:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
3.15%
Probability of exploitation in next 30 days
EPSS Percentile
86.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0315 is in the 80th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

debianpatch availablevia nvd_reference
View patch
denopatch availablevia llm_extracted
Fixed in: 2.4.3
View patch
denopatch availablevia llm_extracted
Fixed in: 3.1.1
View patch
libreofficepatch availablevia llm_extracted
Fixed in: 3.1.1
View patch
libreofficepatch availablevia llm_extracted
Fixed in: 2.4.3
View patch
nessuspatch availablevia llm_extracted
Fixed in: 3.1.1
postgresqlpatch availablevia llm_extracted
Fixed in: 2.4.3
View patch
postgresqlpatch availablevia llm_extracted
Fixed in: 3.1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: libxml2-0:2.5.10-15
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: libxml2-0:2.6.26-2.1.2.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: libxml-1:1.8.17-9.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: libxml2-0:2.6.16-12.7
View patch

Vendor Advisories (5)

redhatCVE-2009-2414Moderate

mingw32-libxml2: Stack overflow by parsing root XML element DTD definition

Aug 10, 2009
denollm-deno-7d5d7f9a1d7396e4

Manipulated XML documents can lead to arbitrary code execution

postgresqlllm-postgresql-6ea8630e811ae3c8

Manipulated XML documents can lead to arbitrary code execution

libreofficellm-libreoffice-23dd6b0df537c565

Manipulated XML documents can lead to arbitrary code execution

nessusllm-nessus-f95bc72128810fdc

Manipulated XML documents can lead to arbitrary code execution

References

googlechromereleases.blogspot.com / 2009/08/stable-update-security-fixes.html
lists.apple.com / archives/security-announce/2009/Nov/msg00000.html
lists.apple.com / archives/security-announce/2009/Nov/msg00001.html
lists.apple.com / archives/security-announce/2010/Jun/msg00003.html
lists.opensuse.org / opensuse-security-announce/2009-09/msg00001.html
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/35036
secunia.com / advisories/36207
secunia.com / advisories/36338
secunia.com / advisories/36417
secunia.com / advisories/36631
secunia.com / advisories/37346
secunia.com / advisories/37471
git.gnome.org / browse/libxml2/commit
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10129
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8639
support.apple.com / kb/HT3937
support.apple.com / kb/HT3949
support.apple.com / kb/HT4225
redhat.com / archives/fedora-package-announce/2009-August/msg00537.html
redhat.com / archives/fedora-package-announce/2009-August/msg00547.html
redhat.com / archives/fedora-package-announce/2009-August/msg00642.html
cert.fi / en/reports/2009/vulnerability2009085.html
codenomicon.com / labs/xml
debian.org / security/2009/dsa-1859
Patch
mail-archive.com / debian-bugs-dist%40lists.debian.org/msg678527.html
networkworld.com / columnists/2009/080509-xml-flaw.html
openoffice.org / security/cves/CVE-2009-2414-2416.html
securityfocus.com / archive/1/507985/100/0/threaded
securityfocus.com / bid/36010
ubuntu.com / usn/USN-815-1
vmware.com / security/advisories/VMSA-2009-0016.html
vupen.com / english/advisories/2009/2420
vupen.com / english/advisories/2009/3184
vupen.com / english/advisories/2009/3217
vupen.com / english/advisories/2009/3316