Xmlsoft

Libxml2

97 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.05%
  • Published 10.07.2013 10:55:02
  • Last modified 11.04.2025 00:51:21

parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for ...

Exploit
  • EPSS 0.95%
  • Published 25.04.2013 23:55:01
  • Last modified 11.04.2025 00:51:21

Multiple use-after-free vulnerabilities in libxml2 2.9.0 and possibly other versions might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to the (1) htmlParseChunk and (2...

  • EPSS 0.25%
  • Published 25.04.2013 23:55:01
  • Last modified 11.04.2025 00:51:21

libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entit...

  • EPSS 0.73%
  • Published 21.12.2012 05:46:14
  • Last modified 11.04.2025 00:51:21

libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.

  • EPSS 2.07%
  • Published 28.11.2012 01:55:01
  • Last modified 11.04.2025 00:51:21

Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute ar...

  • EPSS 1.05%
  • Published 31.08.2012 19:55:01
  • Last modified 11.04.2025 00:51:21

libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have un...

Exploit
  • EPSS 17.55%
  • Published 02.09.2011 16:55:03
  • Last modified 11.04.2025 00:51:21

Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file tha...

Exploit
  • EPSS 1.62%
  • Published 07.12.2010 21:00:09
  • Last modified 11.04.2025 00:51:21

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath...

Exploit
  • EPSS 0.57%
  • Published 17.11.2010 01:00:02
  • Last modified 11.04.2025 00:51:21

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to ca...

  • EPSS 0.19%
  • Published 11.08.2009 18:30:00
  • Last modified 09.04.2025 00:30:58

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...