← Vulnerability feed

Vulnerability record · CVE-2008-4409 · published 3 October 2008

CVE-2008-4409: Xmlsoft libxml2 vulnerability

Xmlsoft · Libxml2

libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and CVE-2008-3281.

5.0 CVSS 2.0 Medium EPSS 8.5% · top 5.1% CWE-399 · CWE-399
5.0CVSS 2.0 base score
8.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
36References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and CVE-2008-3281.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugzilla.gnome.org/show_bug.cgi?id=554660 Exploit
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html
http://openwall.com/lists/oss-security/2008/10/02/4
http://secunia.com/advisories/32130
http://secunia.com/advisories/32175
http://secunia.com/advisories/32974
http://secunia.com/advisories/35379
http://security.gentoo.org/glsa/glsa-200812-06.xml
http://support.apple.com/kb/HT3613
http://support.apple.com/kb/HT3639
http://www.mandriva.com/security/advisories?name=MDVSA-2008:212
http://www.securityfocus.com/bid/31555
http://www.vupen.com/english/advisories/2009/1522
http://www.vupen.com/english/advisories/2009/1621
https://exchange.xforce.ibmcloud.com/vulnerabilities/45633
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00125.html
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00130.html
http://bugzilla.gnome.org/show_bug.cgi?id=554660 Exploit
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html
http://openwall.com/lists/oss-security/2008/10/02/4
http://secunia.com/advisories/32130
http://secunia.com/advisories/32175
http://secunia.com/advisories/32974
http://secunia.com/advisories/35379
http://security.gentoo.org/glsa/glsa-200812-06.xml
http://support.apple.com/kb/HT3613
http://support.apple.com/kb/HT3639
http://www.mandriva.com/security/advisories?name=MDVSA-2008:212
http://www.securityfocus.com/bid/31555
http://www.vupen.com/english/advisories/2009/1522
http://www.vupen.com/english/advisories/2009/1621
https://exchange.xforce.ibmcloud.com/vulnerabilities/45633
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00125.html
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00130.html

Track CVE-2008-4409 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3529Xmlsoft libxml2 memory buffer overflow vulnerabilityHeap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a …EPSS 23%10.0CVE-2004-0989Xmlsoft libxml vulnerabilityMultiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code vi…EPSS 22%9.8CVE-2024-56171Xmlsoft libxml2 use after free vulnerabilitylibxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. …EPSS 1.2%9.8CVE-2017-7375Xmlsoft libxml2 xml external entity (xxe) vulnerabilityA flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD valida…EPSS 2.6%9.8CVE-2017-7376Xmlsoft libxml2 memory buffer overflow vulnerabilityBuffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.EPSS 23%9.8CVE-2017-16931Xmlsoft libxml2 memory buffer overflow vulnerabilityparser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the …EPSS 4.3%9.8CVE-2016-4658Apple iphone os memory buffer overflow vulnerabilityxpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does…EPSS 8.6%9.8CVE-2016-4448Hp icewall federation agent vulnerabilityFormat string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.EPSS 7.0%

Source: NIST National Vulnerability Database (record CVE-2008-4409), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.