← Vulnerability feed

Vulnerability record · CVE-2011-2516 · published 11 July 2011

CVE-2011-2516: Apache xml security for c\+\+ vulnerability

Apache · Xml Security For C\+\+

Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.

5.0 CVSS 2.0 Medium EPSS 7.7% · top 5.6% CWE-189 · CWE-189
5.0CVSS 2.0 base score
7.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
32References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/063159.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/063229.html
http://santuario.apache.org/secadv/CVE-2011-2516.txt Vendor Advisory
http://secunia.com/advisories/45151 Vendor Advisory
http://secunia.com/advisories/45191 Vendor Advisory
http://secunia.com/advisories/45198
http://secunia.com/advisories/45491
http://shibboleth.internet2.edu/secadv/secadv_20110706.txt Vendor Advisory
http://www.debian.org/security/2011/dsa-2277
http://www.securityfocus.com/archive/1/518756/100/0/threaded
http://www.securityfocus.com/bid/48611
http://www.securitytracker.com/id?1025755
https://exchange.xforce.ibmcloud.com/vulnerabilities/68420
https://issues.apache.org/jira/browse/SANTUARIO-271 Exploit
https://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3%40%3Ccommits.santuario.apa
https://lists.apache.org/thread.html/r1c07a561426ec5579073046ad7f4207cdcef452bb3100abaf908e0cd%40%3Ccommits.santuario.ap
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/063159.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/063229.html
http://santuario.apache.org/secadv/CVE-2011-2516.txt Vendor Advisory
http://secunia.com/advisories/45151 Vendor Advisory
http://secunia.com/advisories/45191 Vendor Advisory
http://secunia.com/advisories/45198
http://secunia.com/advisories/45491
http://shibboleth.internet2.edu/secadv/secadv_20110706.txt Vendor Advisory
http://www.debian.org/security/2011/dsa-2277
http://www.securityfocus.com/archive/1/518756/100/0/threaded
http://www.securityfocus.com/bid/48611
http://www.securitytracker.com/id?1025755
https://exchange.xforce.ibmcloud.com/vulnerabilities/68420
https://issues.apache.org/jira/browse/SANTUARIO-271 Exploit
https://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3%40%3Ccommits.santuario.apa
https://lists.apache.org/thread.html/r1c07a561426ec5579073046ad7f4207cdcef452bb3100abaf908e0cd%40%3Ccommits.santuario.ap

Track CVE-2011-2516 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2013-2210Apache xml security for c\+\+ memory buffer overflow vulnerabilityHeap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 al…EPSS 6.0%7.5CVE-2013-2154Apache xml security for c\+\+ memory buffer overflow vulnerabilityStack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka …EPSS 8.0%7.5CVE-2013-2156Apache xml security for c\+\+ memory buffer overflow vulnerabilityHeap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010315.cpp) in Apache Santuario XML Security for C++…EPSS 8.4%5.8CVE-2013-2155Apache xml security for c\+\+ improper input validation vulnerabilityApache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to ca…EPSS 5.8%4.3CVE-2013-2153Apache xml security for c\+\+ vulnerabilityThe XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allo…EPSS 4.8%8.4CVE-2013-2094Linux Kernel perf_swevent_init Integer Type Flaw Enables Local Privilege EscalationThe perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, allowing a local user to…KEVEPSS 48%analysed

Source: NIST National Vulnerability Database (record CVE-2011-2516), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.