CVE-2021-42521
Last modified
CVE-2021-42521 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that NULL pointer dereference may crash the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vtk | Vtk | <= 9.0.0 |
References
- https://gitlab.kitware.com/vtk/vtk/issues/17818Exploit, Issue Tracking, Third Party Advisory
- https://gitlab.kitware.com/vtk/vtk/issues/17818Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-42521?
How severe is CVE-2021-42521?
How do I fix CVE-2021-42521?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-4247A vulnerability has been found in OWASP NodeGoat and classif…7.5
- CVE-2021-4248A vulnerability was found in kapetan dns up to 6.1.0. It has…9.8
- CVE-2021-4249A vulnerability was found in xml-conduit. It has been classi…7.5
- CVE-2021-4250A vulnerability classified as problematic has been found in …7.5
- CVE-2021-4251A vulnerability classified as problematic was found in as. T…6.1
- CVE-2021-4252A vulnerability, which was classified as problematic, has be…6.1
- CVE-2021-42522There is a Information Disclosure vulnerability in anjuta/pl…7.5
- CVE-2021-42523There are two Information Disclosure vulnerabilities in colo…7.5
- CVE-2021-42524Adobe Animate version 21.0.9 (and earlier) are affected by a…7.8
- CVE-2021-42525Acrobat Animate versions 21.0.9 (and earlier)is affected by …3.3
- CVE-2021-42526Adobe Premiere Elements 20210809.daily.2242976 (and earlier)…7.8
- CVE-2021-42527Adobe Premiere Elements 20210809.daily.2242976 (and earlier)…7.8
Are you affected by CVE-2021-42521?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
