Vulnerabilities
Vulnerable Software
Xmlsoft:  >> Libxml2  >> 2.11.8  Security Vulnerabilities
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
CVSS Score
7.8
EPSS Score
0.011
Published
2025-02-18
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
CVSS Score
9.1
EPSS Score
0.012
Published
2024-12-23


Contact Us

Shodan ® - All rights reserved