← Vulnerability feed

Vulnerability record · CVE-2024-23807 · published 29 February 2024

CVE-2024-23807: Apache xerces-c\+\+ use after free vulnerability

Apache · Xerces C\+\+

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.

9.8 CVSS 3.1 Critical EPSS 1.5% · top 27.1% CWE-416 · Use after free
9.8CVSS 3.1 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/apache/xerces-c/pull/54 ExploitPatchThird Party Advisory
https://lists.apache.org/thread/c497tgn864tsbm8w0bo3f0d81s07zk9r Mailing ListPatchVendor Advisory
https://github.com/apache/xerces-c/pull/54 ExploitPatchThird Party Advisory
https://lists.apache.org/thread/c497tgn864tsbm8w0bo3f0d81s07zk9r Mailing ListPatchVendor Advisory

Track CVE-2024-23807 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-12627Apache xerces-c\+\+ null pointer dereference vulnerabilityIn Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain condition…EPSS 8.4%9.8CVE-2016-2099Apache xerces-c\+\+ vulnerabilityUse-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspe…EPSS 6.8%8.8CVE-2023-37536Apache xerces-c\+\+ integer overflow vulnerabilityAn integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.EPSS 1.4%8.1CVE-2018-1311Apache xerces-c\+\+ use after free vulnerabilityThe Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been …EPSS 9.5%7.8CVE-2008-4482Apache xerces-c\+\+ improper input validation vulnerabilityThe XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML sc…EPSS 4.2%7.5CVE-2012-0880Apache xerces-c\+\+ vulnerabilityApache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes has…EPSS 4.4%7.5CVE-2016-4463Apache xerces-c\+\+ memory buffer overflow vulnerabilityStack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.EPSS 14%5.0CVE-2015-0252Debian linux improper input validation vulnerabilityinternal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafte…EPSS 40%

Source: NIST National Vulnerability Database (record CVE-2024-23807), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.