Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fh2x-v9fw-7v49

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

** DISPUTED ** libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser."

** DISPUTED ** libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser."

EPSS

Процентиль: 86%
0.02935
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 4.7
ubuntu
почти 9 лет назад

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.

CVSS3: 5.5
redhat
больше 9 лет назад

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.

CVSS3: 4.7
nvd
почти 9 лет назад

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.

CVSS3: 4.7
debian
почти 9 лет назад

libxml2 2.9.4, when used in recover mode, allows remote attackers to c ...

CVSS3: 5.3
fstec
почти 9 лет назад

Уязвимость библиотеки Libxml2, связанная с ошибками разыменования указателя, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 86%
0.02935
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-476