云虫漏洞情报

CVE-2022-50999 - Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service. - 漏洞详情

漏洞编号:CVE-2022-50999

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2022-50999

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-119

发布/更新时间:2026-08-25 / 2026-08-28

漏洞描述

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

相关链接

相关漏洞

« 返回首页