← Vulnerability feed

Vulnerability record · CVE-2009-1885 · published 11 August 2009

CVE-2009-1885: Apache xerces-c\+\+ memory buffer overflow vulnerability

Apache · Xerces C\+\+

Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.

4.3 CVSS 2.0 Medium EPSS 5.3% · top 7.7% CWE-119 · Memory buffer overflow
4.3CVSS 2.0 base score
5.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/36201 Vendor Advisory
http://svn.apache.org/viewvc/xerces/c/trunk/src/xercesc/validators/DTD/DTDScanner.cpp?r1=781488&r2=781487&pathrev=781488
http://svn.apache.org/viewvc?view=rev&revision=781488 Exploit
http://www.cert.fi/en/reports/2009/vulnerability2009085.html
http://www.codenomicon.com/labs/xml/
http://www.mandriva.com/security/advisories?name=MDVSA-2009:223
http://www.networkworld.com/columnists/2009/080509-xml-flaw.html
http://www.securityfocus.com/bid/35986
http://www.vupen.com/english/advisories/2009/2196 PatchVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=515515 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/52321
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01001.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01099.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01136.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01150.html
http://secunia.com/advisories/36201 Vendor Advisory
http://svn.apache.org/viewvc/xerces/c/trunk/src/xercesc/validators/DTD/DTDScanner.cpp?r1=781488&r2=781487&pathrev=781488
http://svn.apache.org/viewvc?view=rev&revision=781488 Exploit
http://www.cert.fi/en/reports/2009/vulnerability2009085.html
http://www.codenomicon.com/labs/xml/
http://www.mandriva.com/security/advisories?name=MDVSA-2009:223
http://www.networkworld.com/columnists/2009/080509-xml-flaw.html
http://www.securityfocus.com/bid/35986
http://www.vupen.com/english/advisories/2009/2196 PatchVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=515515 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/52321
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01001.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01099.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01136.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01150.html

Track CVE-2009-1885 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-23807Apache xerces-c\+\+ use after free vulnerabilityThe Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users…EPSS 1.5%9.8CVE-2017-12627Apache xerces-c\+\+ null pointer dereference vulnerabilityIn Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain condition…EPSS 8.4%9.8CVE-2016-2099Apache xerces-c\+\+ vulnerabilityUse-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspe…EPSS 6.8%8.8CVE-2023-37536Apache xerces-c\+\+ integer overflow vulnerabilityAn integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.EPSS 1.4%8.1CVE-2018-1311Apache xerces-c\+\+ use after free vulnerabilityThe Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been …EPSS 9.5%7.8CVE-2008-4482Apache xerces-c\+\+ improper input validation vulnerabilityThe XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML sc…EPSS 4.2%7.5CVE-2012-0880Apache xerces-c\+\+ vulnerabilityApache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes has…EPSS 4.4%7.5CVE-2016-4463Apache xerces-c\+\+ memory buffer overflow vulnerabilityStack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2009-1885), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.