Логотип exploitDog
bind:"CVE-2025-8732"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-8732"

Количество 9

Количество 9

ubuntu логотип

CVE-2025-8732

5 месяцев назад

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2025-8732

5 месяцев назад

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2025-8732

5 месяцев назад

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
EPSS: Низкий
msrc логотип

CVE-2025-8732

4 месяца назад

libxml2 xmlcatalog xmlParseSGMLCatalog recursion

EPSS: Низкий
debian логотип

CVE-2025-8732

5 месяцев назад

A vulnerability was found in libxml2 up to 2.14.5. It has been declare ...

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-vr42-4x2q-392x

5 месяцев назад

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4115-1

около 2 месяцев назад

Security update for libxml2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4104-1

2 месяца назад

Security update for libxml2

EPSS: Низкий
redos логотип

ROS-20251111-01

2 месяца назад

Множественные уязвимости libxml2

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-8732

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2025-8732

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-8732

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
0%
Низкий
5 месяцев назад
msrc логотип
CVE-2025-8732

libxml2 xmlcatalog xmlParseSGMLCatalog recursion

0%
Низкий
4 месяца назад
debian логотип
CVE-2025-8732

A vulnerability was found in libxml2 up to 2.14.5. It has been declare ...

CVSS3: 3.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-vr42-4x2q-392x

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4115-1

Security update for libxml2

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4104-1

Security update for libxml2

2 месяца назад
redos логотип
ROS-20251111-01

Множественные уязвимости libxml2

CVSS3: 5.5
2 месяца назад

Уязвимостей на страницу