Логотип exploitDog
bind: "CVE-2022-2309"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-2309"

Количество 12

Количество 12

ubuntu логотип

CVE-2022-2309

почти 3 года назад

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-2309

почти 3 года назад

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-2309

почти 3 года назад

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-2309

почти 3 года назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-2309

почти 3 года назад

NULL Pointer Dereference allows attackers to cause a denial of service ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2908-1

почти 3 года назад

Security update for python-lxml

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2878-1

почти 3 года назад

Security update for python-lxml

EPSS: Низкий
redos логотип

ROS-20250128-05

5 месяцев назад

Уязвимость python3-lxml

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2022:8226

больше 2 лет назад

Moderate: python-lxml security update

EPSS: Низкий
github логотип

GHSA-wrxv-2j5q-m38w

почти 3 года назад

lxml NULL Pointer Dereference allows attackers to cause a denial of service

CVSS3: 5.3
EPSS: Низкий
oracle-oval логотип

ELSA-2022-8226

больше 2 лет назад

ELSA-2022-8226: python-lxml security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-01012

почти 3 года назад

Уязвимость библиотеки для обработки разметки XML и HTML Lxml, связанная с разыменованием указателя NULL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-2309

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-2309

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-2309

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 7.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2022-2309

NULL Pointer Dereference allows attackers to cause a denial of service ...

CVSS3: 7.5
1%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2908-1

Security update for python-lxml

1%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2878-1

Security update for python-lxml

1%
Низкий
почти 3 года назад
redos логотип
ROS-20250128-05

Уязвимость python3-lxml

CVSS3: 7.5
1%
Низкий
5 месяцев назад
rocky логотип
RLSA-2022:8226

Moderate: python-lxml security update

1%
Низкий
больше 2 лет назад
github логотип
GHSA-wrxv-2j5q-m38w

lxml NULL Pointer Dereference allows attackers to cause a denial of service

CVSS3: 5.3
1%
Низкий
почти 3 года назад
oracle-oval логотип
ELSA-2022-8226

ELSA-2022-8226: python-lxml security update (MODERATE)

больше 2 лет назад
fstec логотип
BDU:2025-01012

Уязвимость библиотеки для обработки разметки XML и HTML Lxml, связанная с разыменованием указателя NULL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
почти 3 года назад

Уязвимостей на страницу