
We found results for “”
CVE-2018-9466
Good to know:

Date: November 19, 2024
In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation
Language: C
Severity Score
Severity Score
Weakness Type (CWE)
Out-of-bounds Write
CWE-787Top Fix

Upgrade Version
Upgrade to version StrawberryPerl64 - no_fix;libxml2-vc140-static-32_64 - 2.9.4.1;libopc - no_fix;gstreamer-android-shared - no_fix;libxml2-vc140-static-64 - no_fix;libxml2 - 2.9.10;gettext - 0.20.1;StrawberryPerlPortable64 - no_fix;gstreamer-android-shared-armv7 - no_fix;AsanTestDependencies - no_fix;kew_libxml2 - no_fix;org.webjars.npm:libxmljs-mt:no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |