← back
CVE-2024-25062

CVE-2024-25062

CVSS 7.5 HIGHEPSS 1.4%CWE-416
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 1.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
04 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →