CVE-2017-16932

HIGH

libxml2 <2.9.5 - Buffer Overflow

Title source: llm
STIX 2.1

Description

parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.

Scores

CVSS v3 7.5
EPSS 0.2199
EPSS Percentile 95.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-835
Status published
Products (2)
rubygems/nokogiri 0 - 1.8.1RubyGems
xmlsoft/libxml2 < 2.9.4
Published Nov 23, 2017
Tracked Since Feb 18, 2026