CVE-2006-10003 - CVE House
Back to Database
Status published Unknown CVE-2006-10003

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack

Vulnerability Description

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer. The bug can be observed when parsing an XML file with very deep element nesting

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-10003

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

XML::Parser
Vulnerable Versions:
0

Timeline

Official Publish: March 19th, 2026
Last Modified: July 15th, 2026
Added to House: July 18th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)