GNOME libxslt
cpe:2.3:a:xmlsoft:libxslt:*:*:*:*:*:*:*
- < 1.1.43
A use-after-free vulnerability has been identified in libxslt versions prior to 1.1.43. The issue arises in numbers.c, where an XPath context node can be altered during nested XPath evaluations but not restored. This vulnerability is associated with the functions xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
Exploitation of this vulnerability leads to a use-after-free condition, which can potentially be exploited to execute arbitrary code or cause a denial-of-service.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.