8.8
CVSSv3

CVE-2021-3518

Published: 18/05/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

There's a flaw in libxml2 in versions prior to 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xmlsoft libxml2

debian debian linux 9.0

redhat jboss core services -

redhat enterprise linux 8.0

fedoraproject fedora 33

fedoraproject fedora 34

netapp ontap select deploy administration utility -

netapp clustered data ontap -

netapp clustered data ontap antivirus connector -

netapp snapdrive -

netapp active iq unified manager -

netapp manageability software development kit -

netapp hci_h410c_firmware -

oracle peoplesoft enterprise peopletools 8.58

oracle enterprise manager base platform 13.4.0.0

oracle enterprise manager ops center 12.4.0.0

oracle enterprise manager base platform 13.5.0.0

oracle mysql workbench

oracle real user experience insight 13.4.1.0

oracle real user experience insight 13.5.1.0

oracle communications cloud native core network function cloud native environment 1.10.0

Vendor Advisories

Debian Bug report logs - #987737 libxml2: CVE-2021-3518 Package: src:libxml2; Maintainer for src:libxml2 is Debian XML/SGML Group <debian-xml-sgml-pkgs@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 28 Apr 2021 19:27:01 UTC Severity: important Tags: security, upstream Foun ...
Synopsis Important: Red Hat JBoss Core Services Apache HTTP Server 2437 SP11 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Updated packages that provide Red Hat JBoss Core Services Apache HTTP Server 2 ...
Synopsis Important: Red Hat JBoss Core Services Apache HTTP Server 2437 SP11 security update Type/Severity Security Advisory: Important Topic Red Hat JBoss Core Services Apache HTTP Server 2437 Service Pack 11 zip release for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows is availableRed Hat Product Securit ...
Synopsis Moderate: OpenShift Container Platform 4103 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4103 is now available withupdates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact of ...
Synopsis Important: Service Telemetry Framework 14 security update Type/Severity Security Advisory: Important Topic An update is now available for Service Telemetry Framework 14 for RHEL 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which g ...
parserc in libxml2 before 295 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name (CVE-2017-16931) GNOME project libxml2 v2910 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entitiesc The issue has been ...
There's a flaw in libxml2's xmllint An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free The greatest impact of this flaw is to confidentiality, integrity, and availability (CVE-2021-3516) There's a flaw in libxml2 An attacker who is able to submit a crafted file to be processed by an applic ...
No description is available for this CVE ...
A use-after-free security issue was found in libxml2 in xmlXIncludeDoProcess() in xincludec when processing crafted files ...

ICS Advisories

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-07-21-1 iOS 147 and iPadOS 147 iOS 147 and iPadOS 147 addresses the following issues Information about the security content is also available at supportapplecom/HT212601 iOS 147 released July 19, 2021; iPadOS 147 released July 21, 2021 ActionKit Available for: iPhon ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-07-21-2 macOS Big Sur 115 macOS Big Sur 115 addresses the following issues Information about the security content is also available at supportapplecom/HT212602 AMD Kernel Available for: macOS Big Sur Impact: An application may be able to execute arbitrary code with kerne ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-07-21-6 tvOS 147 tvOS 147 addresses the following issues Information about the security content is also available at supportapplecom/HT212604 Audio Available for: Apple TV 4K and Apple TV HD Impact: A local attacker may be able to cause unexpected application termination ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-07-21-5 watchOS 76 watchOS 76 addresses the following issues Information about the security content is also available at supportapplecom/HT212605 ActionKit Available for: Apple Watch Series 3 and later Impact: A shortcut may be able to bypass Internet permission requirem ...