Vulnerability · NVD
CVE-2025-7425
CVE-2025-7425 : high severity (CVSS 7.8). No tracked catalog app is linked to this CVE.
- Severity (CVSS)
- 7.8
- Exploitation
- 0.4 %
- Tracked apps
- 0
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.
Show raw CVSS vector
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.