Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w8fw-fj9q-vcjj

Опубликовано: 17 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 2.9

Описание

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

EPSS

Процентиль: 5%
0.00023
Низкий

2.9 Low

CVSS3

Дефекты

CWE-125
CWE-1284

Связанные уязвимости

CVSS3: 2.9
ubuntu
2 месяца назад

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

CVSS3: 2.9
redhat
2 месяца назад

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

CVSS3: 2.9
nvd
2 месяца назад

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

CVSS3: 7.5
msrc
24 дня назад

Описание отсутствует

CVSS3: 2.9
debian
2 месяца назад

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNod ...

EPSS

Процентиль: 5%
0.00023
Низкий

2.9 Low

CVSS3

Дефекты

CWE-125
CWE-1284