6.4
CVSSv2

CVE-2017-8872

Published: 10/05/2017 Updated: 10/09/2020
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 571
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows malicious users to cause a denial of service (buffer over-read) or information disclosure.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xmlsoft libxml2 2.9.4

Vendor Advisories

Debian Bug report logs - #862450 libxml2: CVE-2017-8872: Out-of-bounds read in htmlParseTryOrFinish Package: src:libxml2; Maintainer for src:libxml2 is Debian XML/SGML Group <debian-xml-sgml-pkgs@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 12 May 2017 19:45:02 UTC Severi ...
The htmlParseTryOrFinish function in HTMLparserc in libxml2 294 allows attackers to cause a denial of service (buffer over-read) or information disclosure ...

ICS Advisories

Hitachi Energy APM Edge
Critical Infrastructure Sectors: Energy