Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-40896

Опубликовано: 23 дек. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.1

Описание

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

РелизСтатусПримечание
devel

not-affected

2.12.7+dfsg+really2.9.14-0.2ubuntu2
esm-infra-legacy/trusty

not-affected

debian: Vulnerable code introduced later in 2.11.0
esm-infra/bionic

not-affected

debian: Vulnerable code introduced later in 2.11.0
esm-infra/focal

not-affected

debian: Vulnerable code introduced later in 2.11.0
esm-infra/xenial

not-affected

debian: Vulnerable code introduced later in 2.11.0
focal

not-affected

debian: Vulnerable code introduced later in 2.11.0
jammy

not-affected

debian: Vulnerable code introduced later in 2.11.0
noble

not-affected

debian: Vulnerable code introduced later in 2.11.0
oracular

released

2.12.7+dfsg-3ubuntu0.1
upstream

released

2.11.9

Показывать по

EPSS

Процентиль: 67%
0.00553
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
redhat
около 1 года назад

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

CVSS3: 9.1
nvd
около 1 года назад

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

CVSS3: 9.1
msrc
12 месяцев назад

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

CVSS3: 9.1
debian
около 1 года назад

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.1 ...

suse-cvrf
11 месяцев назад

Security update for qt6-webengine

EPSS

Процентиль: 67%
0.00553
Низкий

9.1 Critical

CVSS3