VYPR
Medium severity6.5NVD Advisory· Published Aug 11, 2009· Updated Apr 23, 2026

CVE-2009-2416

CVE-2009-2416

Description

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.

Affected products

33
  • cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
    Range: <4.0.4
  • cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
    Range: <2.0.172.43
  • cpe:2.3:a:sun:openoffice.org:*:*:*:*:*:*:*:*
    Range: >=2.0.0,<2.4.3
  • cpe:2.3:a:vmware:vcenter_server:4.0:-:*:*:*:*:*:*
  • cpe:2.3:a:vmware:vma:4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:xmlsoft:libxml:1.8.17:*:*:*:*:*:*:*
  • Xmlsoft/Libxml25 versions
    cpe:2.3:a:xmlsoft:libxml2:2.5.10:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:xmlsoft:libxml2:2.5.10:*:*:*:*:*:*:*
    • cpe:2.3:a:xmlsoft:libxml2:2.6.16:*:*:*:*:*:*:*
    • cpe:2.3:a:xmlsoft:libxml2:2.6.26:*:*:*:*:*:*:*
    • cpe:2.3:a:xmlsoft:libxml2:2.6.27:*:*:*:*:*:*:*
    • cpe:2.3:a:xmlsoft:libxml2:2.6.32:*:*:*:*:*:*:*
  • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
    Range: >=2.0,<4.0
  • cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
    Range: <10.4.11
  • cpe:2.3:o:apple:mac_os_x_server:*:*:*:*:*:*:*:*
    Range: <10.4.11
  • cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*
  • cpe:2.3:o:opensuse:opensuse:*:*:*:*:*:*:*:*
    Range: >=10.3,<=11.1
  • cpe:2.3:o:redhat:enterprise_linux:3.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:redhat:enterprise_linux:3.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux:4.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise:10.0:-:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:suse:linux_enterprise:10.0:-:*:*:*:*:*:*
    • cpe:2.3:o:suse:linux_enterprise:11.0:-:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
  • VMware/Esx3 versions
    cpe:2.3:o:vmware:esx:3.0.3:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:vmware:esx:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esx:3.5:*:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esx:4.0:*:*:*:*:*:*:*
  • VMware/Esxi2 versions
    cpe:2.3:o:vmware:esxi:3.5:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:vmware:esxi:3.5:*:*:*:*:*:*:*
    • cpe:2.3:o:vmware:esxi:4.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

36

News mentions

0

No linked articles in our index yet.