CVE detail
CVE-2023-45322 — CVE-2023-45322
Published 2023-10-06 · Modified 2026-06-17 · Vendor xmlsoft · Product libxml2 · Source nvd
MEDIUM
severity
CVSS-derived band
0.0083
EPSS probability
exploitation probability, 30d
54.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References