ZeroHour

CVE-2022-40304

CVSS 3.1
7.8 high
EPSS
7%p94
Published
()
Modified
Description

An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.

Vendors
xmlsoftnetappapple
Products
libxml2, active iq unified manager, clustered data ontap, clustered data ontap antivirus connector, manageability software development kit, smi-s provider, snapmanager, h300s firmware, h500s firmware, h700s firmware, h410s firmware, h410c firmware
Weakness
CWE-415
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news