ZeroHour

CVE-2022-23308

CVSS 3.1
7.5 high
EPSS
6%p93
Published
()
Modified
Description

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

Vendors
xmlsoftfedoraprojectdebianapplenetapporacle
Products
libxml2, fedora, debian linux, ipados, iphone os, mac os x, macos, tvos, watchos, active iq unified manager, clustered data ontap, clustered data ontap antivirus connector
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.