CVE-2008-3529 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 23.4% (pctl 98)
Patch early
A public exploit exists.
Description
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 23.37% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-09-12 |
| Last modified | 2026-06-16 |
Affected (6)
| Vendor | Product |
|---|---|
| apple | iphone os |
| apple | mac os x |
| apple | safari |
| canonical | ubuntu linux |
| debian | debian linux |
| xmlsoft | libxml2 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apple Safari - RSS 'feed://' Buffer Overflow via libxml2 (PoC) | 2009-05-26 |
References
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
- http://lists.apple.com/archives/security-announce/2009/May/msg00000.html
- http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html
- http://secunia.com/advisories/31558
- http://secunia.com/advisories/31855
- http://secunia.com/advisories/31860
- http://secunia.com/advisories/31868
- http://secunia.com/advisories/31982
- http://secunia.com/advisories/32265
- http://secunia.com/advisories/32280
- http://secunia.com/advisories/32807
- http://secunia.com/advisories/32974
- http://secunia.com/advisories/33715
- http://secunia.com/advisories/33722
- http://secunia.com/advisories/35056
- http://secunia.com/advisories/35074
- http://secunia.com/advisories/35379
- http://secunia.com/advisories/36173
- http://secunia.com/advisories/36235
→ the Explorer · watch your stack · NVD