← All CVEs

CVE-2022-40303

high · 7.5

An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.

7.5
CVSS
23.0%
EPSS (exploit prob.)
98th
EPSS percentile
2022-11-23
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-190

Affected products

VendorProductAffected versions
xmlsoftlibxml2< 2.10.3
netappactive_iq_unified_managerall versions
netappclustered_data_ontapall versions
netappclustered_data_ontap_antivirus_connectorall versions
netappnetapp_manageability_sdkall versions
netappontap_select_deploy_administration_utilityall versions
netappsnapmanagerall versions
appleipados< 15.7.2
appleiphone_os< 15.7.2
applemacos>= 11.0, < 11.7.2
applemacos>= 12.0, < 12.6.2
appletvos< 16.2
applewatchos< 9.2
netapph300s_firmwareall versions
netapph300sall versions
netapph500s_firmwareall versions
netapph500sall versions
netapph700s_firmwareall versions
netapph700sall versions
netapph410s_firmwareall versions
netapph410sall versions
netapph410c_firmwareall versions
netapph410call versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-40303