CVE-2018-11210: TINYXML2 Project TINYXML2

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is due to improper use of the library and not a vulnerability in tinyxml2

Affected products

Published 2018-05-16. Last modified 2026-06-17.