7.8
CVSSv2

CVE-2008-4482

Published: 08/10/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The XML parser in Xerces-C++ prior to 3.0.0 allows context-dependent malicious users to cause a denial of service (stack consumption and crash) via an XML schema definition with a large maxOccurs value, which triggers excessive memory consumption during validation of an XML file.

Vulnerable Product Search on Vulmon Subscribe to Product

apache xerces-c\\+\\+ 2.4.0

apache xerces-c\\+\\+ 2.3.0

apache xerces-c\\+\\+ 1.4.0

apache xerces-c\\+\\+ 1.3.0

apache xerces-c\\+\\+ 2.7.0

apache xerces-c\\+\\+ 2.6.0

apache xerces-c\\+\\+ 1.6.0

apache xerces-c\\+\\+ 1.5.0

apache xerces-c\\+\\+ 2.2.0

apache xerces-c\\+\\+ 2.1.0

apache xerces-c\\+\\+ 1.2.0

apache xerces-c\\+\\+ 1.1.0

apache xerces-c\\+\\+ 2.5.0

apache xerces-c\\+\\+

apache xerces-c\\+\\+ 2.0.0

apache xerces-c\\+\\+ 1.7.0

apache xerces-c\\+\\+ 1.0.1

apache xerces-c\\+\\+ 1.0.0