CVE-2015-8710: libxml2: out-of-bounds memory access when parsing an unclosed HTML comment

Severity: Critical

CVSS Score: 9.8

The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed HTML comment.