cbcvebase.
CVE-2022-23308
published 2022-02-26

CVE-2022-23308: valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
appleios_15.5_and_ipados
appleipados< 15.515.5
appleiphone_os< 15.515.5
applemac_os_x
applemac_os_x>= 10.15.0 < 10.15.710.15.7
applemacos>= 11.6.0 < 11.6.611.6.6
applemacos>= 12.0 < 12.412.4
applemacos_big_sur
applemacos_monterey
applesecurity_update_2022-004_catalina
appletvos< 15.515.5
appletvos
applewatchos< 8.68.6
applewatchos
debiandebian_linux
debianlibxml2< libxml2 2.9.13+dfsg-1 (bookworm)libxml2 2.9.13+dfsg-1 (bookworm)
fedoraprojectfedora
googlechrome_chrome
msrccbl2_libxml2_2.9.13-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_libxml2_2.9.13-1_on_cbl_mariner_1.0
nokogirinokogiri>= 0 < 1.13.21.13.2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa8.8HIGH
osv8.8HIGH