CVE-2023-45322
libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."
- Xmlsoft libxml2
- ≤ 2.11.5
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.8% (54th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2023-10-06
CVE-2023-45322 at NVD
No indexed exploits for CVE-2023-45322 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-45322 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.