cbcvebase.
CVE-2021-3518
published 2021-05-18

CVE-2021-3518: There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
appleios_14.7_and_ipados
debiandebian_linux
debianlibxml2< libxml2 2.9.10+dfsg-6.6 (bookworm)libxml2 2.9.10+dfsg-6.6 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrccm1_libxml2_2.9.12-1_on_cbl_mariner_1.0
nokogirinokogiri>= 0 < 1.11.41.11.4
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oracleenterprise_manager_ops_center
oraclemysql_workbench<= 8.0.26
oraclepeoplesoft_enterprise_peopletools
oraclereal_user_experience_insight
oraclereal_user_experience_insight
paloaltopan-os
redhatenterprise_linux
xmlsoftlibxml2< 2.9.112.9.11
xmlsoftlibxml2
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-6.1ubuntu1.42.9.4+dfsg1-6.1ubuntu1.4
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-5ubuntu0.20.04.12.9.10+dfsg-5ubuntu0.20.04.1

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa7.5HIGH
osv9.1CRITICAL