Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-25062


An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.


Published

2024-02-04T16:15:45.120

Last Modified

2025-05-09T18:16:03.707

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-416
  • Type: Secondary
    CWE-416

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application xmlsoft libxml2 < 2.11.7 Yes
Application xmlsoft libxml2 < 2.12.5 Yes

References