CVE-2016-4570: Debian Linux

Medium severity, CVSS 5.5. EPSS: 1.6% chance of exploitation in the next 30 days.

The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.

Affected products

Published 2017-02-03. Last modified 2026-06-17.