CVE-2020-24977
PoC —CVSS 3.1
6.5 medium
EPSS
4%p89
Published
()
Modified
Description
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
- Vendors
- xmlsoftdebianfedoraprojectopensusenetapporacle
- Products
- libxml2, debian linux, fedora, leap, active iq unified manager, clustered data ontap, clustered data ontap antivirus connector, inventory collect tool, manageability software development kit, snapdrive, hci h410c firmware, communications cloud native core network function cloud native environment
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.