CVE-2016-4463
HIGHApache Xerces-C++ < 3.1.4 - Denial of Service via Deeply Nested DTD
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-4463. PoCs published by arntsonl.
AI-analyzed exploit summary The repository contains a functional exploit for CVE-2016-4463, a stack-based buffer overflow in Apache Xerces-C++ before 3.1.4. The exploit generates a malformed XML file that triggers the overflow when parsed by vulnerable versions of Xerces-C++.
Description
Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.
Exploits (1)
The repository contains a functional exploit for CVE-2016-4463, a stack-based buffer overflow in Apache Xerces-C++ before 3.1.4. The exploit generates a malformed XML file that triggers the overflow when parsed by vulnerable versions of Xerces-C++.
References (15)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H