CVE-2015-8710
CRITICALlibxml2 < 2.9.3 - Heap-Based Buffer Overflow via Unclosed HTML Comment
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-8710. PoCs published by Karm.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2015-8710, a vulnerability in libxml2 that involves uninitialized memory reads during HTML parsing. The PoC demonstrates the issue by parsing a malformed HTML fragment, triggering a conditional jump based on uninitialized values.
Description
The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed HTML comment.
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2015-8710, a vulnerability in libxml2 that involves uninitialized memory reads during HTML parsing. The PoC demonstrates the issue by parsing a malformed HTML fragment, triggering a conditional jump based on uninitialized values.
References (9)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H