CVE-2008-4225

Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (infinite loop) via a large XML document.

Published: 2008-11-25 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2008-4225 is rated High Risk (65/100): CVSS High severity, with medium exploitation likelihood (EPSS 4.92%). Core evidence: EPSS rose +2.44% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2008-4225

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-12 2.47% 4.92% +2.44%
2 2026-05-11 1.40% 2.47% +1.07%
3 2025-08-30 1.40%

Full EPSS history (11 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2008-4225

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.8 2.0 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 6.9 [email protected]

Weakness enumeration for CVE-2008-4225

OS Trackers for CVE-2008-4225

vendor priority summary link
debian not yet assigned CVE-2008-4225 not yet assigned priority: Debian including 1 source packages (libxml2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2008-4225
gentoo normal CVE-2008-4225: 1 GLSA(s) (200812-06), 1 atom(s) (dev-libs/libxml2); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2008-4225
redhat medium https://access.redhat.com/security/cve/CVE-2008-4225
suse high CVE-2008-4225 severity important: SUSE including 88 source package names (libxml2, libxml2-2-2.11.6-2.1, …), 125 product×package rows across 36 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP1, … (36 product lines)): Fixed 121, Known Not Affected 4. https://www.suse.com/security/cve/CVE-2008-4225/
ubuntu medium CVE-2008-4225 medium priority: Ubuntu including 1 source packages (libxml2), 5 status rows across 5 suites (dapper, gutsy, hardy, intrepid, upstream): released 4, needs-triage 1. https://ubuntu.com/security/CVE-2008-4225

Affected software / configurations for CVE-2008-4225

Vendor Product Version Raw CPE
xmlsoft libxml 2.7.2 cpe:2.3:a:xmlsoft:libxml:2.7.2:*:*:*:*:*:*:*

References for CVE-2008-4225

URL Tags
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html
http://secunia.com/advisories/32762 Vendor Advisory
http://secunia.com/advisories/32764 Patch
http://secunia.com/advisories/32766 Vendor Advisory
http://secunia.com/advisories/32773 Vendor Advisory
http://secunia.com/advisories/32802 Vendor Advisory
http://secunia.com/advisories/32807 Vendor Advisory
http://secunia.com/advisories/32811 Vendor Advisory
http://secunia.com/advisories/32974
http://secunia.com/advisories/33417
http://secunia.com/advisories/33746
http://secunia.com/advisories/33792
http://secunia.com/advisories/34247
http://secunia.com/advisories/35379
http://secunia.com/advisories/36173
http://secunia.com/advisories/36235
http://security.gentoo.org/glsa/glsa-200812-06.xml
http://securitytracker.com/id?1021239
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.473974
http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-03-1
http://sunsolve.sun.com/search/document.do?assetkey=1-21-141243-01-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-251406-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-261688-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-265329-1
http://support.apple.com/kb/HT3613
http://support.apple.com/kb/HT3639
http://support.avaya.com/elmodocs2/security/ASA-2009-002.htm
http://support.avaya.com/elmodocs2/security/ASA-2009-067.htm
http://wiki.rpath.com/Advisories:rPSA-2008-0325
http://www.debian.org/security/2008/dsa-1666 Patch
http://www.mandriva.com/security/advisories?name=MDVSA-2008:231
http://www.osvdb.org/49992
http://www.redhat.com/support/errata/RHSA-2008-0988.html
http://www.securityfocus.com/bid/32331 Patch
http://www.ubuntu.com/usn/usn-673-1
http://www.vmware.com/security/advisories/VMSA-2009-0001.html
http://www.vupen.com/english/advisories/2008/3176
http://www.vupen.com/english/advisories/2009/0034
http://www.vupen.com/english/advisories/2009/0301
http://www.vupen.com/english/advisories/2009/0323
http://www.vupen.com/english/advisories/2009/1522
http://www.vupen.com/english/advisories/2009/1621
https://admin.fedoraproject.org/updates/libxml2-2.7.2-2.fc10 Patch
https://admin.fedoraproject.org/updates/libxml2-2.7.2-2.fc9 Patch
https://bugzilla.redhat.com/show_bug.cgi?id=470480
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10025
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6234
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6415
https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00472.html
https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00513.html
cvelogic Threat Intelligence