Metrics
Affected Vendors & Products
Tue, 12 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gnome
Gnome libxml2 |
|
Vendors & Products |
Gnome
Gnome libxml2 |
Tue, 12 Aug 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Fri, 08 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 08 Aug 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all." | |
Title | libxml2 xmlcatalog xmlParseSGMLCatalog recursion | |
Weaknesses | CWE-404 CWE-674 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-08T16:32:06.990Z
Updated: 2025-08-08T17:12:15.735Z
Reserved: 2025-08-08T07:49:27.806Z
Link: CVE-2025-8732

Updated: 2025-08-08T17:12:12.366Z

Status : Awaiting Analysis
Published: 2025-08-08T17:15:30.583
Modified: 2025-08-08T20:30:18.180
Link: CVE-2025-8732
