CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2017-7375

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1940%
EPSS Percentile6.56th
Published2018年2月19日
Last Modified2025年12月3日

Vulnerability Description

A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).

Affected Platforms (CPE)

📦
Xmlsoft

Libxml2

<= 2.9.4
💻
Debian

Debian Linux

= 7.0
💻
Debian

Debian Linux

= 8.0
💻
Debian

Debian Linux

= 9.0
💻
Google

Android

= 4.4.4
💻
Google

Android

= 5.0.2
💻
Google

Android

= 5.1.1
💻
Google

Android

= 6.0
💻
Google

Android

= 6.0.1
💻
Google

Android

= 7.0
💻
Google

Android

= 7.1.1
💻
Google

Android

= 7.1.2
📦
Xmlsoft

Libxml2

= 2.9.4
📦
Xmlsoft

Libxml2

= 2.9.4

References & Advisories

相關漏洞威脅