Логотип exploitDog
bind: "CVE-2025-8732"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-8732"

Количество 9

Количество 9

ubuntu логотип

CVE-2025-8732

4 месяца назад

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2025-8732

4 месяца назад

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2025-8732

4 месяца назад

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
EPSS: Низкий
msrc логотип

CVE-2025-8732

3 месяца назад

libxml2 xmlcatalog xmlParseSGMLCatalog recursion

EPSS: Низкий
debian логотип

CVE-2025-8732

4 месяца назад

A vulnerability was found in libxml2 up to 2.14.5. It has been declare ...

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-vr42-4x2q-392x

4 месяца назад

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4115-1

14 дней назад

Security update for libxml2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4104-1

17 дней назад

Security update for libxml2

EPSS: Низкий
redos логотип

ROS-20251111-01

20 дней назад

Множественные уязвимости libxml2

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-8732

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-8732

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-8732

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
0%
Низкий
4 месяца назад
msrc логотип
CVE-2025-8732

libxml2 xmlcatalog xmlParseSGMLCatalog recursion

0%
Низкий
3 месяца назад
debian логотип
CVE-2025-8732

A vulnerability was found in libxml2 up to 2.14.5. It has been declare ...

CVSS3: 3.3
0%
Низкий
4 месяца назад
github логотип
GHSA-vr42-4x2q-392x

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."

CVSS3: 3.3
0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:4115-1

Security update for libxml2

14 дней назад
suse-cvrf логотип
SUSE-SU-2025:4104-1

Security update for libxml2

17 дней назад
redos логотип
ROS-20251111-01

Множественные уязвимости libxml2

CVSS3: 5.5
20 дней назад

Уязвимостей на страницу