Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-25062

Опубликовано: 04 фев. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
Версия до 2.11.7 (исключая)
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
Версия от 2.12.0 (включая) до 2.12.5 (исключая)

EPSS

Процентиль: 69%
0.01364
Низкий

7.5 High

CVSS3

Дефекты

CWE-416
CWE-416

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.

CVSS3: 7.5
redhat
больше 2 лет назад

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.

CVSS3: 7.5
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 7.5
debian
больше 2 лет назад

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.1 ...

suse-cvrf
около 2 лет назад

Security update for libxml2

EPSS

Процентиль: 69%
0.01364
Низкий

7.5 High

CVSS3

Дефекты

CWE-416
CWE-416