CVE-2015-8242
Severity
5.8MEDIUM
EPSS
1.4%
top 19.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 15
Latest updateMay 14
Description
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
CVSS vector
AV:N/AC:M/C:P/I:N/A:PExploitability: 8.6 | Impact: 4.9
Affected Packages12 packages
Also affects: Ubuntu Linux 12.04, 14.04, 15.04, 15.10
🔴Vulnerability Details
4📋Vendor Advisories
7Debian▶
CVE-2015-8242: libxml2 - The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser ...↗2015
💬Community
1Bugzilla
▶