A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .xml file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Oct 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .xml file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | |
| Weaknesses | CWE-416 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: talos
Published: 2025-10-28T13:45:38.831Z
Updated: 2025-10-28T16:04:54.333Z
Reserved: 2025-08-13T12:32:34.071Z
Link: CVE-2025-53814
Updated: 2025-10-28T16:04:50.825Z
Status : Received
Published: 2025-10-28T14:15:58.973
Modified: 2025-10-28T14:15:58.973
Link: CVE-2025-53814
No data.