PatchSiren

Mini Xml Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Mini Xml Project CVE published 2017-02-03

CVE-2016-4571

CVE-2016-4571 is a denial-of-service issue in Mini-XML's mxml_write_node function in mxml-file.c. The vulnerable path can be triggered by crafted XML and may consume excessive stack, preventing normal service. NVD lists Mini-XML 2.9 and 2.7 as affected, with possibly earlier versions also impacted. The CVE was published on 2017-02-03 and later updated by NVD on 2026-05-13.

MEDIUM Mini Xml Project CVE published 2017-02-03

CVE-2016-4570

CVE-2016-4570 describes a denial-of-service issue in Mini-XML (mxml) where the mxmlDelete function in mxml-node.c can consume stack space when processing crafted XML. The public record ties the issue to mxml 2.7 and 2.9, with possibly earlier versions also affected. Organizations that parse untrusted XML with affected builds should treat this as a stability risk and verify whether their packaging or downs [truncated]