CVE-2025-24855 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is…
High CVSS: 7.8

CVE-2025-24855

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
Vendor
Xmlsoft
Product
Libxslt
CWE
CWE-416
Yayın Tarihi
2025-03-14 02:15:15
Güncelleme
2025-11-03 22:18:40
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar