Lucene search

K
cve[email protected]CVE-2022-40304
HistoryNov 23, 2022 - 6:15 p.m.

CVE-2022-40304

2022-11-2318:15:12
CWE-415
web.nvd.nist.gov
230
3
cve-2022-40304
libxml2
xml entity
corruption
logic errors
double-free
vulnerability
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

38.5%

An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.

Affected configurations

NVD
Node
xmlsoftlibxml2Range<2.10.3
Node
netappactive_iq_unified_managerMatch-vmware_vsphere
OR
netappclustered_data_ontapMatch-
OR
netappclustered_data_ontap_antivirus_connectorMatch-
OR
netappmanageability_software_development_kitMatch-
OR
netappsmi-s_providerMatch-
OR
netappsnapmanagerMatch-hyper-v
Node
netapph300s_firmwareMatch-
AND
netapph300sMatch-
Node
netapph500s_firmwareMatch-
AND
netapph500sMatch-
Node
netapph700s_firmwareMatch-
AND
netapph700sMatch-
Node
netapph410s_firmwareMatch-
AND
netapph410sMatch-
Node
netapph410c_firmwareMatch-
AND
netapph410cMatch-
Node
appleipadosRange<15.7.2
OR
appleiphone_osRange<15.7.2
OR
applemacosRange11.011.7.2
OR
applemacosRange12.012.6.2
OR
appletvosRange<16.2
OR
applewatchosRange<9.2
CPENameOperatorVersion
xmlsoft:libxml2xmlsoft libxml2lt2.10.3

Social References

More

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

38.5%