Xmlsoft

Libxml2

97 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.41%
  • Published 11.08.2009 18:30:00
  • Last modified 09.04.2025 00:30:58

Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related ...

Exploit
  • EPSS 10.6%
  • Published 03.10.2008 17:41:40
  • Last modified 09.04.2025 00:30:58

libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a c...

Exploit
  • EPSS 58.86%
  • Published 12.09.2008 16:56:20
  • Last modified 09.04.2025 00:30:58

Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.

  • EPSS 0.8%
  • Published 27.08.2008 20:41:00
  • Last modified 09.04.2025 00:30:58

libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.

Exploit
  • EPSS 28.23%
  • Published 01.03.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy...

  • EPSS 43.7%
  • Published 15.03.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.

  • EPSS 0.85%
  • Published 31.12.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nes...