ZeroHour

CVE-2020-24977

PoC
CVSS 3.1
6.5 medium
EPSS
4%p89
Published
()
Modified
Description

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

Vendors
xmlsoftdebianfedoraprojectopensusenetapporacle
Products
libxml2, debian linux, fedora, leap, active iq unified manager, clustered data ontap, clustered data ontap antivirus connector, inventory collect tool, manageability software development kit, snapdrive, hci h410c firmware, communications cloud native core network function cloud native environment
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

In the news

No ingested article mentions this CVE yet.