Impact
The vulnerability in libxml2 prior to version 2.15.4 is a stack-based buffer overflow caused by an uncontrolled strcat in xmlSnprintfElements. This flaw may allow an attacker to corrupt memory, potentially enabling arbitrary code execution or denial‑of‑service. The weakness is classified as CWE‑120 and CWE‑121.
Affected Systems
The affected product is libxml2 from xmlsoft for all releases before 2.15.4. Users of any older libxml2 version are at risk.
Risk and Exploitability
The severity is CVSS 8, indicating a high impact. The EPSS score is 0.00136, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation has not been observed in the wild. The attack likely requires the ability to supply crafted XML input processed by the vulnerable library.
OpenCVE Enrichment