5
CVSSv2

CVE-2016-4463

Published: 08/07/2016 Updated: 12/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Stack-based buffer overflow in Apache Xerces-C++ prior to 3.1.4 allows context-dependent malicious users to cause a denial of service via a deeply nested DTD.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache xerces-c\\+\\+

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #828990 xerces-c: CVE-2016-4463 Package: src:xerces-c; Maintainer for src:xerces-c is William Blough <bblough@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 29 Jun 2016 14:45:10 UTC Severity: important Tags: fixed-upstream, patch, security, upstream Found in ve ...
Synopsis Moderate: xerces-c security update Type/Severity Security Advisory: Moderate Topic An update for xerces-c is now available for Red Hat Enterprise Linux 74 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring ...
Synopsis Moderate: xerces-c security update Type/Severity Security Advisory: Moderate Topic An update for xerces-c is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Moderate: xerces-c security update Type/Severity Security Advisory: Moderate Topic An update for xerces-c is now available for Red Hat Enterprise Linux 75 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring ...
Brandon Perry discovered that xerces-c, a validating XML parser library for C++, fails to successfully parse a DTD that is deeply nested, causing a stack overflow A remote unauthenticated attacker can take advantage of this flaw to cause a denial of service against applications using the xerces-c library Additionally this update includes an enhan ...
A stack exhaustion flaw was found in the way Xerces-C XML parser handled deeply nested DTDs An attacker could potentially use this flaw to crash an application using Xerces-C by tricking it into processing specially crafted data(CVE-2016-4463) ...
A stack exhaustion flaw was found in the way Xerces-C XML parser handled deeply nested DTDs An attacker could potentially use this flaw to crash an application using Xerces-C by tricking it into processing specially crafted data ...

Github Repositories

Proof of concept for CVE-2016-4463

CVE-2016-4463 An implementation of the CVE-2016-4463 exploit Xerces 313 and below exploit I meant to get this submitted to Exploit-DB, but I do not have a good go-to app to test this against Java OpenSAML should be vulnerable, but it will take some time to explore this