Impact
The vulnerability is a classic out‑of‑bounds read in the xmlFAParsePosCharGroup function of libxml2. An attacker can trigger the NXT macro in xmlregexp to read memory beyond the intended buffer, potentially exposing process memory contents at the time the library parses an XML document.
Affected Systems
This flaw exists in all releases of the libxml2 library before version 2.15.4, sold and maintained by XMLSoft. Any program that links against a vulnerable libxml2 DLL or shared object may be impacted, regardless of the language or platform.
Risk and Exploitability
The CVSS score of 2.9 indicates a low to moderate threat. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, implying a low likelihood of widespread exploitation. An attacker would need to supply malicious XML input to a vulnerable application, which could be local or remote depending on the application's network exposure.
OpenCVE Enrichment