CVE-2006-10002Disclosure(toddr / xml\)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes. A :utf8 PerlIO layer, parse_stream() in Expat.xs could overflow the XML input buffer because Perl's read() returns decoded characters while SvPV() gives back multi-byte UTF-8 bytes that can exceed the pre-allocated buffer size. This can cause heap corruption (double free or corruption) and crashes.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-176

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xml\

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Disclouser: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-19); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
xml\

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-19: 1Mentions · 2026-03-20: 1Mentions · 2026-03-23: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-23: 103-1903-2003-23
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Disclouser
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-191
Disclosure1
2026-03-201
General1
2026-03-231
Disclouser1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN XML::Parser through 2.47 CVE-2006-10002: Could overflow the pre-allocated buffer, cause heap corruption and crashes https://www.openwall.com/lists/oss-security/2026/03/19/1 CVE-2006-10003: Off-by-one heap buffer overflow in st_serial_stack https://www.openwall.com/lists/oss-security/2026/03/19/2

    Post summary

    The text announces two heap buffer overflow vulnerabilities (CVE-2006-10002 and CVE-2006-10003) in Perl CPAN XML::Parser 2.47, providing technical details and links to discussion threads but no PoC, exploitation evidence, or patch information.

    01050533
    4.4K followersView on X
  • CVE@CVEnew
    Disclouser

    CVE-2006-10002 XML::Parser versions through 2.47 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes. A :utf8 Perl… https://www.cve.org/CVERecord?id=CVE-2006-10002

    Post summary

    The entry outlines a buffer overflow vulnerability in XML::Parser that can lead to heap corruption and application crashes.

    00000133
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2006-10002 - TODDR - XML::Parser - https://www.redpacketsecurity.com/cve-alert-cve-2006-10002-toddr-xml-parser/ #OSINT #ThreatIntel #CyberSecurity #cve-2006-10002 #toddr #xml-parser

    Post summary

    The tweet merely links to a CVE‑alert page for CVE‑2006‑10002, providing no further information on exploitation, patches, or technical details.

    0000069
    3.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptoddrxml\\--

Explore more