← Vulnerability feed

Vulnerability record · CVE-2011-1944 · published 2 September 2011

CVE-2011-1944: Xmlsoft libxml2 vulnerability

Xmlsoft · Libxml2

Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.

9.3 CVSS 2.0 High EPSS 13% · top 3.7% CWE-189 · CWE-189
9.3CVSS 2.0 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
40References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://git.gnome.org/browse/libxml2/commit/?id=d7958b21e7f8c447a26bb2436f08402b2c308be4 Patch
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041
http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062238.html ExploitPatch
http://lists.opensuse.org/opensuse-updates/2011-07/msg00035.html
http://rhn.redhat.com/errata/RHSA-2013-0217.html
http://scarybeastsecurity.blogspot.com/2011/05/libxml-vulnerability-and-interesting.html PatchVendor Advisory
http://secunia.com/advisories/44711 Vendor Advisory
http://support.apple.com/kb/HT5281
http://support.apple.com/kb/HT5503
http://ubuntu.com/usn/usn-1153-1
http://www.debian.org/security/2011/dsa-2255
http://www.mandriva.com/security/advisories?name=MDVSA-2011:131
http://www.openwall.com/lists/oss-security/2011/05/31/8 ExploitPatch
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
http://www.osvdb.org/73248
http://www.redhat.com/support/errata/RHSA-2011-1749.html
http://www.securityfocus.com/bid/48056 Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=709747 ExploitPatch
http://git.gnome.org/browse/libxml2/commit/?id=d7958b21e7f8c447a26bb2436f08402b2c308be4 Patch
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041
http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062238.html ExploitPatch
http://lists.opensuse.org/opensuse-updates/2011-07/msg00035.html
http://rhn.redhat.com/errata/RHSA-2013-0217.html
http://scarybeastsecurity.blogspot.com/2011/05/libxml-vulnerability-and-interesting.html PatchVendor Advisory
http://secunia.com/advisories/44711 Vendor Advisory
http://support.apple.com/kb/HT5281
http://support.apple.com/kb/HT5503
http://ubuntu.com/usn/usn-1153-1
http://www.debian.org/security/2011/dsa-2255
http://www.mandriva.com/security/advisories?name=MDVSA-2011:131
http://www.openwall.com/lists/oss-security/2011/05/31/8 ExploitPatch
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
http://www.osvdb.org/73248
http://www.redhat.com/support/errata/RHSA-2011-1749.html
http://www.securityfocus.com/bid/48056 Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=709747 ExploitPatch

Track CVE-2011-1944 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-4226Xmlsoft libxml vulnerabilityInteger overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruptio…EPSS 4.1%10.0CVE-2008-3529Xmlsoft libxml2 memory buffer overflow vulnerabilityHeap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a …EPSS 23%10.0CVE-2004-0989Xmlsoft libxml vulnerabilityMultiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code vi…EPSS 22%9.8CVE-2024-56171Xmlsoft libxml2 use after free vulnerabilitylibxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. …EPSS 1.2%9.8CVE-2017-7375Xmlsoft libxml2 xml external entity (xxe) vulnerabilityA flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD valida…EPSS 2.6%9.8CVE-2017-7376Xmlsoft libxml2 memory buffer overflow vulnerabilityBuffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.EPSS 23%9.8CVE-2017-16931Xmlsoft libxml2 memory buffer overflow vulnerabilityparser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the …EPSS 4.3%9.8CVE-2016-4658Apple iphone os memory buffer overflow vulnerabilityxpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does…EPSS 8.6%

Source: NIST National Vulnerability Database (record CVE-2011-1944), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.