AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-9048

HIGH · CVSS 7.5 EPSS 4.89%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-05-18 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2017-9048
Severity
HIGH
CVSS
7.5
EPSS
4.89%

Original NVD Description

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. At the end of the routine, the function may strcat two more characters without checking whether the current strlen(buf) + 2 < size. This vulnerability causes programs that use libxml2, such as PHP, to crash.

Related CVEs

Other vulnerabilities affecting the same vendor(s)