libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
                
            References
                    | Link | Resource | 
|---|---|
| https://gitlab.gnome.org/GNOME/libxml2/-/issues/847 | Issue Tracking | 
| https://issues.oss-fuzz.com/issues/392687022 | Issue Tracking | 
| https://security.netapp.com/advisory/ntap-20250321-0006/ | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| AND | 
 
 | 
Configuration 3 (hide)
| AND | 
 
 | 
Configuration 4 (hide)
| AND | 
 
 | 
Configuration 5 (hide)
| AND | 
 
 | 
Configuration 6 (hide)
| AND | 
 
 | 
Configuration 7 (hide)
| AND | 
 
 | 
History
                    16 Oct 2025, 19:34
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://gitlab.gnome.org/GNOME/libxml2/-/issues/847 - Issue Tracking | |
| References | () https://issues.oss-fuzz.com/issues/392687022 - Issue Tracking | |
| References | () https://security.netapp.com/advisory/ntap-20250321-0006/ - Third Party Advisory | |
| CPE | cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:* cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:manageability_software_development_kit:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:* | |
| First Time | Netapp h500s Firmware Netapp Netapp manageability Software Development Kit Netapp solidfire \& Hci Management Node Netapp h410s Firmware Netapp hci Compute Node Netapp h700s Firmware Netapp h410c Netapp h500s Xmlsoft libxml2 Netapp h300s Xmlsoft Netapp h300s Firmware Netapp h410s Netapp active Iq Unified Manager Netapp h410c Firmware Netapp ontap Netapp h700s | 
21 Mar 2025, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| References | 
 | 
18 Feb 2025, 23:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-02-18 23:15
Updated : 2025-10-16 19:34
NVD link : CVE-2025-24928
Mitre link : CVE-2025-24928
CVE.ORG link : CVE-2025-24928
JSON object : View
Products Affected
                netapp
- h500s_firmware
- h700s_firmware
- h410s_firmware
- h700s
- h500s
- ontap
- h410s
- active_iq_unified_manager
- h410c
- h410c_firmware
- h300s
- solidfire_\&_hci_management_node
- h300s_firmware
- hci_compute_node
- manageability_software_development_kit
xmlsoft
- libxml2
CWE
                
                    
                        
                        CWE-121
                        
            Stack-based Buffer Overflow
