CVE-2016-9597
- EPSS 1.33%
- Veröffentlicht 30.07.2018 14:29:02
- Zuletzt bearbeitet 21.11.2024 03:01:28
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression C...
CVE-2016-3705
- EPSS 1.03%
- Veröffentlicht 17.05.2016 14:08:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and applic...
CVE-2016-3627
- EPSS 0.29%
- Veröffentlicht 17.05.2016 14:08:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML doc...
- EPSS 0.33%
- Veröffentlicht 15.12.2015 21:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds ...
CVE-2015-8242
- EPSS 1.66%
- Veröffentlicht 15.12.2015 21:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive informati...
CVE-2015-8241
- EPSS 1.75%
- Veröffentlicht 15.12.2015 21:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML dat...
- EPSS 4.25%
- Veröffentlicht 15.12.2015 21:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
- EPSS 2.95%
- Veröffentlicht 15.12.2015 21:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
- EPSS 3.44%
- Veröffentlicht 15.12.2015 21:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
- EPSS 3.44%
- Veröffentlicht 15.12.2015 21:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.