Vulnerability Report

CVE-2011-1944

Title: Xmlsoft Libxml2 RCE

Memory Corruption

Proof Of Concept

PoC Available for CVE-2011-1944

CWE Category CWE-189
Published Date Sep 02, 2011
Modified Date Jun 16, 2026
Exploit Status Available
Score 9.3 CVSS v2.0
Exploit Probability (EPSS)
13.43%

Vulnerability Summary

CVE-2011-1944: Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.

Impacted Vendors

Reference Links

http://git.gnome.org/browse/libxml2/commit/?id=d7958b21e7f8c447a26bb2436f08402b2c308be4 http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041 http://lists.apple.com/archives/security-announce/2012/May/msg00001.html http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062238.html http://lists.opensuse.org/opensuse-updates/2011-07/msg00035.html http://rhn.redhat.com/errata/RHSA-2013-0217.html http://scarybeastsecurity.blogspot.com/2011/05/libxml-vulnerability-and-interesting.html http://secunia.com/advisories/44711 http://support.apple.com/kb/HT5281 http://support.apple.com/kb/HT5503 http://ubuntu.com/usn/usn-1153-1 http://www.debian.org/security/2011/dsa-2255 http://www.mandriva.com/security/advisories?name=MDVSA-2011:131 http://www.openwall.com/lists/oss-security/2011/05/31/8 http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html http://www.osvdb.org/73248 http://www.redhat.com/support/errata/RHSA-2011-1749.html http://www.securityfocus.com/bid/48056 https://bugzilla.redhat.com/show_bug.cgi?id=709747 http://git.gnome.org/browse/libxml2/commit/?id=d7958b21e7f8c447a26bb2436f08402b2c308be4 http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041 http://lists.apple.com/archives/security-announce/2012/May/msg00001.html http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062238.html http://lists.opensuse.org/opensuse-updates/2011-07/msg00035.html http://rhn.redhat.com/errata/RHSA-2013-0217.html http://scarybeastsecurity.blogspot.com/2011/05/libxml-vulnerability-and-interesting.html http://secunia.com/advisories/44711 http://support.apple.com/kb/HT5281 http://support.apple.com/kb/HT5503 http://ubuntu.com/usn/usn-1153-1 http://www.debian.org/security/2011/dsa-2255 http://www.mandriva.com/security/advisories?name=MDVSA-2011:131 http://www.openwall.com/lists/oss-security/2011/05/31/8 http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html http://www.osvdb.org/73248 http://www.redhat.com/support/errata/RHSA-2011-1749.html http://www.securityfocus.com/bid/48056 https://bugzilla.redhat.com/show_bug.cgi?id=709747
CVSS v2.0
Source Entity [email protected]
Severity HIGH
9.3
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:M/Au:N/C:C/I:C/A:C

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2011-1944 Exploits & PoCs (Proof Of Concept)

Exploit-DB https://www.exploit-db.com/exploits/35810
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected Stack

No specific products linked.