CVE-2011-1944
- EPSS 23.69%
- Veröffentlicht 02.09.2011 16:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file tha...
CVE-2010-4494
- EPSS 1.44%
- Veröffentlicht 07.12.2010 21:00:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath...
CVE-2010-4008
- EPSS 0.76%
- Veröffentlicht 17.11.2010 01:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to ca...
CVE-2009-2414
- EPSS 1.29%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related ...
CVE-2009-2416
- EPSS 0.5%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
- EPSS 11.3%
- Veröffentlicht 03.10.2008 17:41:40
- Zuletzt bearbeitet 23.04.2026 00:35:47
libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a c...
- EPSS 56.63%
- Veröffentlicht 12.09.2008 16:56:20
- Zuletzt bearbeitet 23.04.2026 00:35:47
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
CVE-2008-3281
- EPSS 0.8%
- Veröffentlicht 27.08.2008 20:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
- EPSS 24.27%
- Veröffentlicht 01.03.2005 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy...
CVE-2004-0110
- EPSS 41.34%
- Veröffentlicht 15.03.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.