VYPR
High severity7.1NVD Advisory· Published Dec 22, 2016· Updated May 6, 2026

CVE-2016-9181

CVE-2016-9181

Description

perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.

Affected products

2
  • cpe:2.3:a:image-info_project:image-info_for_perl:1.16:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:image-info_project:image-info_for_perl:1.16:*:*:*:*:*:*:*
    • cpe:2.3:a:image-info_project:image-info_for_perl:1.30:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.