libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.
2017-04-11T16:59:00.343
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 4.7 (MEDIUM)
AV:N/AC:H/Au:N/C:N/I:N/A:P
4.9
2.9