CVE-2021-3517 Details
Description
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | CISA-ADP |
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xmlsoft libxml2 | < 2.9.11 |
CPE
Remediation
| |
| redhat jboss core services | All versions |
CPE
Remediation
| |
| redhat enterprise linux | 8.0 |
CPE
Remediation
| |
| fedoraproject fedora | 33 34 |
CPE
Remediation
| |
| debian debian linux | 9.0 |
CPE
Remediation
| |
| netapp active iq unified manager | All versions |
CPE
Remediation
| |
| netapp clustered data ontap | All versions |
CPE
Remediation
| |
| netapp clustered data ontap antivirus connector | All versions |
CPE
Remediation
| |
| netapp e-series santricity os controller | >= 11.0.0, <= 11.70.1 |
CPE
Remediation
| |
| netapp e-series santricity storage manager | All versions |
CPE
Remediation
| |
| netapp e-series santricity web services | All versions |
CPE
Remediation
| |
| netapp hci management node | All versions |
CPE
Remediation
| |
| netapp manageability software development kit | All versions |
CPE
Remediation
| |
| netapp oncommand insight | All versions |
CPE
Remediation
| |
| netapp oncommand workflow automation | All versions |
CPE
Remediation
| |
| netapp ontap select deploy administration utility | All versions |
CPE
Remediation
| |
| netapp santricity unified manager | All versions |
CPE
Remediation
| |
| netapp snapdrive | All versions |
CPE
Remediation
| |
| netapp snapmanager | All versions |
CPE
Remediation
| |
| netapp solidfire | All versions |
CPE
Remediation
| |
| netapp hci h410c firmware | All versions |
CPE
Remediation
| |
| netapp hci h410c | All versions |
CPE
Remediation
| |
| oracle communications cloud native core network function cloud native environment | 1.10.0 |
CPE
Remediation
| |
| oracle enterprise manager base platform | 13.4.0.0 13.5.0.0 |
CPE
Remediation
| |
| oracle mysql workbench | <= 8.0.26 |
CPE
Remediation
| |
| oracle openjdk | 8 update301 |
CPE
Remediation
| |
| oracle peoplesoft enterprise peopletools | 8.58 |
CPE
Remediation
| |
| oracle real user experience insight | 13.4.1.0 13.5.1.0 |
CPE
Remediation
| |
| oracle zfs storage appliance kit | 8.8 |
CPE
Remediation
| |
Change History
22 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Dec 2, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Oct 5, 2022 | Modified Analysis | [email protected] |
| Jul 25, 2022 | CVE Modified | [email protected] |
| Apr 20, 2022 | CVE Modified | [email protected] |
| Mar 1, 2022 | Modified Analysis | [email protected] |
| Feb 7, 2022 | CVE Modified | [email protected] |
| Dec 3, 2021 | Modified Analysis | [email protected] |
| Oct 22, 2021 | CVE Modified | [email protected] |
| Oct 20, 2021 | CVE Modified | [email protected] |
| Sep 13, 2021 | Modified Analysis | [email protected] |
| Jul 8, 2021 | CVE Modified | [email protected] |
| Jul 6, 2021 | CVE Modified | [email protected] |
| Jun 29, 2021 | CVE Modified | [email protected] |
| Jun 28, 2021 | CVE Modified | [email protected] |
| Jun 25, 2021 | CVE Modified | [email protected] |
| Jun 14, 2021 | CVE Modified | [email protected] |
| May 25, 2021 | Initial Analysis | [email protected] |