Vulnerabilities > CVE-2025-32414 - Unchecked Return Value vulnerability in Xmlsoft Libxml2

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
xmlsoft
CWE-252

Summary

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw because of a difference between bytes and characters.

Vulnerable Configurations

Part Description Count
Application
Xmlsoft
207

Common Weakness Enumeration (CWE)