CVE-2016-4463: Apache Xerces-C++

High severity, CVSS 7.5. EPSS: 14.1% chance of exploitation in the next 30 days.

Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.

Affected products

  • Apache Xerces-C++: up to and including 3.1.3
  • Debian Debian Linux: version 8.0 only

Published 2016-07-08. Last modified 2026-06-17.