Vulnerability intelligence
CVE-2025-6021
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
CVSS Score
7.5
High
EPSS — Exploit Probability
1.1%
Riskier than 61% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered May 14, 2026 · latest May 14, 2026
Coverage timeline
-
Siemens SIMATIC CN 4100 hit by CVE-2024-47704, urges V5.0 updatewww.cisa.gov · May 14, 2026