CVE-2009-2416 describes multiple use-after-free vulnerabilities in various versions of libxml2 and libxml, affecting numerous products including Apple, Canonical, Debian, Google, and Red Hat. Attackers can exploit these flaws by crafting malicious XML files containing specific Notation or Enumeration attribute types, leading to a denial of service through application crashes. Rated as MEDIUM severity (CVSS 6.5), this vulnerability requires user interaction (UI:R) and has a high impact on availability (A:H), but does not affect confidentiality or integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.17CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxml:1.8.17:*:*:*:*:*:*:* | ||
2.5.10CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxml2:2.5.10:*:*:*:*:*:*:* | ||
2.6.16CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxml2:2.6.16:*:*:*:*:*:*:* | ||
2.6.26CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxml2:2.6.26:*:*:*:*:*:*:* | ||
2.6.27CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxml2:2.6.27:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
mingw32-libxml2: Pointer use-after-free flaws by parsing Notation and Enumeration attribute types
Aug 10, 2009Manipulated XML documents can lead to arbitrary code execution
Manipulated XML documents can lead to arbitrary code execution
Manipulated XML documents can lead to arbitrary code execution
Manipulated XML documents can lead to arbitrary code execution