CVE-2025-24928

Published Feb 18, 2025

Last updated 4 months ago

Overview

Description
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
Source
cve@mitre.org
NVD status
Modified
Products
active_iq_unified_manager, manageability_software_development_kit, ontap, solidfire_\&_hci_management_node, libxml2, hci_compute_node, h410c_firmware, h300s_firmware, h500s_firmware, h700s_firmware, h410s_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
7.7
Impact score
5.2
Exploitability score
2.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
HIGH

Weaknesses

cve@mitre.org
CWE-121

Social media

Hype score
Not currently trending
  1. ⚠️Múltiples vulnerabilidades en Dell Enterprise SONiC ❗CVE-2024-3596 ❗CVE-2025-24928 ❗CVE-2025-27113 ➡️Más info: https://t.co/IH097zEMBh https://t.co/Gur9b4e8Xl

    @CERTpy

    7 Jul 2025

    146 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  2. ⚠️Actualizaciones de seguridad de Tenable para Nessus ❗CVE-2024-40896 ❗CVE-2025-24928 ❗CVE-2025-24914 ➡️Más info: https://t.co/Krrzmwcmpx https://t.co/sJG3arCLMg

    @CERTpy

    23 Apr 2025

    76 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 Lambda Watchdog detected a new HIGH severity CVE 🚨 CVE-2025-24928 was detected in the latest AWS Lambda image scan affecting the libxml2 package in 9 images. Check the full report 👉 https://t.co/6EUGaPyRZk #AWS #Lambda #CVE #CloudSecurity #Serverless

    @LambdaWatchdog

    26 Mar 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. New data shows rising incidence of CVE-2025-27113 and CVE-2025-24928 vulnerabilities. Stay informed: https://t.co/tej1yYFNGt Created by AI. #Android #Cybersecurity

    @Funker_Dev

    12 Mar 2025

    24 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Threat Alert: CVE-2024-56171 &amp- CVE-2025-24928: Libxml2 Flaws Could Lead to Code Execution CVE-2024-56171 CVE-2025-24928 CVE-2025-27113 Severity: 🔴 High Maturity: 💢 Emerging Learn more: https://t.co/bGoZT33ooK #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    25 Feb 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Multiple vulnerabilities (CVE-2024-56171 & CVE-2025-24928) in Libxml2 could lead to code execution & denial of service. Updates (2.12.10 & 2.13.6) are critical for security. 🛡️🔒 #Libxml2 #SecurityUpdate #Germany link: https://t.co/nHacQ7bODu https://t.co/jPoQPpaE2f

    @TweetThreatNews

    24 Feb 2025

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Libxml2にコード実行の脆弱性。CVE-2024-56171とCVE-2025-24928はCVSSスコア7.8で、前者がxmlSchemaIDCFillNodeTables()とxmlSchemaBubbleIDCNodeTables()における解放後メモリ使用。後者はxmlSnprintfElements()におけるスタックベースのバッファオーバーフロー。 https://t.co/QFZqEHeXMC

    @__kokumoto

    24 Feb 2025

    635 Impressions

    1 Retweet

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Two vulnerabilities in Libxml2, CVE-2024-56171 and CVE-2025-24928, may permit code execution, posing significant risks (https://t.co/ukNicN0KUE). Developers using this library should assess exposure promptly. #cybersecurity #CVE

    @adriananglin

    24 Feb 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2024-56171 & CVE-2025-24928: Libxml2 Flaws Could Lead to Code Execution https://t.co/4HgCAbQ9Gx

    @Dinosn

    24 Feb 2025

    2897 Impressions

    8 Retweets

    35 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2025-24928 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an… https://t.co/wSaRtJMqge

    @CVEnew

    18 Feb 2025

    348 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations