Critical severity9.8NVD Advisory· Published May 13, 2016· Updated May 6, 2026
CVE-2016-2099
CVE-2016-2099
Description
Use-after-free vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 3.1.3 and earlier allows context-dependent attackers to have unspecified impact via an invalid character in an XML document.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- lists.opensuse.org/opensuse-updates/2016-07/msg00016.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-07/msg00053.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-09/msg00013.htmlnvd
- www.debian.org/security/2016/dsa-3579nvd
- www.openwall.com/lists/oss-security/2016/05/09/7nvd
- www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlnvd
- www.securityfocus.com/bid/90502nvd
- issues.apache.org/jira/browse/XERCESC-2066nvd
- security.gentoo.org/glsa/201612-46nvd
News mentions
0No linked articles in our index yet.