CVE-2017-15412

CWE-416Use After Free19 documents9 sources
Severity
8.8HIGH
EPSS
1.9%
top 16.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 28
Latest updateMay 14

Description

Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages8 packages

CVEListV5google_chrome_prior_to_63.0.3239.84_unknownGoogle Chrome prior to 63.0.3239.84 unknown
NVDgoogle/chrome< 63.0.3239.84
NVDxmlsoft/libxml2< 2.9.5
Debianlibxml2< 2.9.4+dfsg1-5.2+3
RubyGemsnokogiri< 1.8.2

Also affects: Debian Linux 7.0, 8.0, 9.0

🔴Vulnerability Details

4
OSV
Nokogiri gem, via libxml, is affected by DoS vulnerabilities2022-05-14
GHSA
Nokogiri gem, via libxml, is affected by DoS vulnerabilities2022-05-14
CVEList
CVE-2017-15412: Use after free in libxml2 before 22018-08-28
OSV
CVE-2017-15412: Use after free in libxml2 before 22018-08-28

📋Vendor Advisories

8
Apple
CVE-2017-15412: tvOS 11.32018-03-29
Apple
CVE-2017-15412: macOS High Sierra 10.13.4, Security Update 2018-002 Sierra, and Security Update 2018-002 El Capitan2018-03-29
Apple
CVE-2017-15412: watchOS 4.32018-03-29
Apple
CVE-2017-15412: iOS 11.32018-03-29
Ubuntu
libxml2 vulnerability2017-12-13

💬Community

6
Bugzilla
CVE-2017-15412 mingw-libxml2: chromium-browser: use after free in libxml [fedora-all]2017-12-11
Bugzilla
CVE-2017-15412 mingw-libxml2: chromium-browser: use after free in libxml [epel-7]2017-12-11
Bugzilla
CVE-2017-15412 libxml2: chromium-browser: use after free in libxml [fedora-all]2017-12-11
Bugzilla
CVE-2017-15407 CVE-2017-15408 CVE-2017-15409 CVE-2017-15410 CVE-2017-15411 CVE-2017-15412 CVE-2017-15413 CVE-2017-15415 CVE-2017-15416 CVE-2017-15417 CVE-2017-15418 CVE-2017-15419 CVE-2017-15420 CVE-22017-12-07
Bugzilla
CVE-2017-15407 CVE-2017-15408 CVE-2017-15409 CVE-2017-15410 CVE-2017-15411 CVE-2017-15412 CVE-2017-15413 CVE-2017-15415 CVE-2017-15416 CVE-2017-15417 CVE-2017-15418 CVE-2017-15419 CVE-2017-15420 CVE-22017-12-07
CVE-2017-15412 (HIGH CVSS 8.8) | Use after free in libxml2 before 2. | cvebase.io