libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to…
mitre·CWE-776·Published 2003-12-31