CVE-2017-9049
- EPSS 0.44%
- Veröffentlicht 18.05.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an in...
CVE-2017-9048
- EPSS 0.58%
- Veröffentlicht 18.05.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. At the end o...
CVE-2017-9047
- EPSS 2.79%
- Veröffentlicht 18.05.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A buffer overflow was discovered in libxml2 20904-GITv2.9.4-16-g0741801. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. The variable len is ass...
CVE-2017-8872
- EPSS 0.18%
- Veröffentlicht 10.05.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure.
CVE-2017-5969
- EPSS 2.71%
- Veröffentlicht 11.04.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should...
CVE-2016-4483
- EPSS 1.27%
- Veröffentlicht 11.04.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE: this vulne...
CVE-2016-9318
- EPSS 0.04%
- Veröffentlicht 16.11.2016 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to condu...
- EPSS 19.34%
- Veröffentlicht 25.09.2016 10:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary co...
CVE-2016-5131
- EPSS 4.2%
- Veröffentlicht 23.07.2016 19:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
CVE-2016-4449
- EPSS 0.12%
- Veröffentlicht 09.06.2016 16:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource con...