← Back to CVE List
Vulnerability Intelligence Report

CVE-2022-23308

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:6.01%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-416 ↗CWE-416 Use After Free

Affected Products & Versions

Vendor Product Affected Versions
xmlsoft libxml2 all
fedoraproject fedora 34
debian debian_linux 9.0
apple ipados all
apple iphone_os all
apple mac_os_x 10.15.7
apple macos all
apple tvos all
apple watchos all
netapp active_iq_unified_manager all
netapp clustered_data_ontap all
netapp clustered_data_ontap_antivirus_connector all
netapp manageability_software_development_kit all
netapp ontap_select_deploy_administration_utility all
netapp smi-s_provider all
netapp snapdrive all
netapp snapmanager all
netapp solidfire\,_enterprise_sds_\&_hci_storage_node all
netapp solidfire_\&_hci_management_node all
netapp bootstrap_os all
netapp hci_compute_node all
netapp h300s_firmware all
netapp h300s all
netapp h500s_firmware all
netapp h500s all
netapp h700s_firmware all
netapp h700s all
netapp h300e_firmware all
netapp h300e all
netapp h500e_firmware all
netapp h500e all
netapp h700e_firmware all
netapp h700e all
netapp h410s_firmware all
netapp h410s all
netapp h410c_firmware all
netapp h410c all
oracle communications_cloud_native_core_binding_support_function 22.2.0
oracle communications_cloud_native_core_network_function_cloud_native_environment 22.1.0
oracle communications_cloud_native_core_network_repository_function 22.1.2, 22.2.0
oracle communications_cloud_native_core_network_slice_selection_function 22.1.1
oracle communications_cloud_native_core_unified_data_repository 22.2.0
oracle mysql_workbench all
oracle zfs_storage_appliance_kit 8.8

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
6.010%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2022-01-17T00:00:00
Published2022-02-26T00:00:00
Last Updated2025-05-05T16:26:56

LINK COPIED TO CLIPBOARD