Логотип exploitDog
bind:"CVE-2022-2309"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-2309"

Количество 12

Количество 12

ubuntu логотип

CVE-2022-2309

больше 3 лет назад

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-2309

больше 3 лет назад

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-2309

больше 3 лет назад

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-2309

больше 3 лет назад

NULL Pointer Dereference in lxml/lxml

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-2309

больше 3 лет назад

NULL Pointer Dereference allows attackers to cause a denial of service ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2908-1

больше 3 лет назад

Security update for python-lxml

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2878-1

больше 3 лет назад

Security update for python-lxml

EPSS: Низкий
redos логотип

ROS-20250128-05

11 месяцев назад

Уязвимость python3-lxml

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2022:8226

около 3 лет назад

Moderate: python-lxml security update

EPSS: Низкий
github логотип

GHSA-wrxv-2j5q-m38w

больше 3 лет назад

lxml NULL Pointer Dereference allows attackers to cause a denial of service

CVSS3: 5.3
EPSS: Низкий
oracle-oval логотип

ELSA-2022-8226

около 3 лет назад

ELSA-2022-8226: python-lxml security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-01012

больше 3 лет назад

Уязвимость библиотеки для обработки разметки XML и HTML Lxml, связанная с разыменованием указателя NULL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-2309

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-2309

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-2309

NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-2309

NULL Pointer Dereference in lxml/lxml

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-2309

NULL Pointer Dereference allows attackers to cause a denial of service ...

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2908-1

Security update for python-lxml

1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2878-1

Security update for python-lxml

1%
Низкий
больше 3 лет назад
redos логотип
ROS-20250128-05

Уязвимость python3-lxml

CVSS3: 7.5
1%
Низкий
11 месяцев назад
rocky логотип
RLSA-2022:8226

Moderate: python-lxml security update

1%
Низкий
около 3 лет назад
github логотип
GHSA-wrxv-2j5q-m38w

lxml NULL Pointer Dereference allows attackers to cause a denial of service

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2022-8226

ELSA-2022-8226: python-lxml security update (MODERATE)

около 3 лет назад
fstec логотип
BDU:2025-01012

Уязвимость библиотеки для обработки разметки XML и HTML Lxml, связанная с разыменованием указателя NULL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу