Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9318

Опубликовано: 16 нояб. 2016
Источник: nvd
CVSS3: 5.5
CVSS2: 4.3
EPSS Низкий

Описание

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
Версия до 2.9.4 (включая)
cpe:2.3:a:xmlsec_project:xmlsec:*:*:*:*:*:*:*:*
Версия до 1.2.23 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

EPSS

Процентиль: 33%
0.00132
Низкий

5.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-611
CWE-611

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 9 лет назад

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

CVSS3: 6.7
redhat
больше 9 лет назад

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.

CVSS3: 5.5
debian
около 9 лет назад

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and ot ...

suse-cvrf
больше 6 лет назад

Security update for libxml2

suse-cvrf
около 9 лет назад

Security update for libxml2

EPSS

Процентиль: 33%
0.00132
Низкий

5.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-611
CWE-611