CVE Feed

    Dashboard / CVE / CVE-2021-42521

    CVE-2021-42521

    There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that NULL pointer dereference may crash the application.

    Published:Aug 25, 2022
    Last Modified:Nov 21, 2024
    EPS:Aug 25, 2022
    EPSS Score:0.00091
    CVSS Score:7.5

    Affected Products

    Vendor
    Vtk
    Product
    Vtk

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High