cbcvebase.
CVE-2021-3537
published 2021-05-14

CVE-2021-3537: A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference…

PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
3.50%
87.9th percentile
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibxml2< libxml2 2.9.10+dfsg-6.6 (bookworm)libxml2 2.9.10+dfsg-6.6 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrccm1_libxml2_2.9.12-1_on_cbl_mariner_1.0
nokogirinokogiri>= 0 < 1.11.41.11.4
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oracleenterprise_manager_ops_center
oraclemysql_workbench<= 8.0.26
oracleopenjdk
oraclepeoplesoft_enterprise_peopletools
oraclereal_user_experience_insight
oraclereal_user_experience_insight
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
xmlsoftlibxml2< 2.9.112.9.11
xmlsoftlibxml2
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.62.9.10+dfsg-6.6
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-6.1ubuntu1.42.9.4+dfsg1-6.1ubuntu1.4

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.