PT-2026-26286 · Unknown+4 · Xml Parser+4

CVE-2006-10003

·

Published

2006-01-01

·

Updated

2026-08-13

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XML::Parser versions through 2.47
Description The software contains a heap buffer overflow in the st serial stack function. This occurs when parsing XML files with deeply nested elements. Specifically, when stackptr equals stacksize - 1, the stack is not expanded, and a new value is written outside the allocated buffer at the stacksize location.
Recommendations Update to a version of XML::Parser later than 2.47.

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:7679
ALSA-2026:7680
ALSA-2026:7681
AZL-80196
BDU:2026-12814
CVE-2006-10003
MGASA-2026-0063
OPENSUSE-SU-2026:10527-1
OPENSUSE-SU-2026:20459-1
RHSA-2026:7679
RHSA-2026:7680
RHSA-2026:7681
RHSA-2026:8577
RHSA-2026:8578
RHSA-2026:8608
RHSA-2026:8609
RHSA-2026:8610
RHSA-2026:9110
RHSA-2026:9246
RHSA-2026:9258
RHSA-2026:9259
RHSA-2026:9605
SUSE-SU-2026:1152-1
SUSE-SU-2026:1153-1
SUSE-SU-2026:20993-1
USN-8174-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Xml Parser