CVE-2022-23308
- EPSS 0.06%
- Veröffentlicht 26.02.2022 05:15:08
- Zuletzt bearbeitet 05.05.2025 17:17:56
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
CVE-2021-3541
- EPSS 0.06%
- Veröffentlicht 09.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:48
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
CVE-2021-3517
- EPSS 0.08%
- Veröffentlicht 19.05.2021 14:15:07
- Zuletzt bearbeitet 02.12.2025 22:16:07
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-o...
CVE-2021-3518
- EPSS 0.23%
- Veröffentlicht 18.05.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:21:44
There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, inte...
CVE-2021-3537
- EPSS 0.11%
- Veröffentlicht 14.05.2021 20:15:16
- Zuletzt bearbeitet 21.11.2024 06:21:47
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could...
CVE-2020-24977
- EPSS 0.5%
- Veröffentlicht 04.09.2020 00:15:10
- Zuletzt bearbeitet 21.11.2024 05:16:15
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
CVE-2020-7595
- EPSS 0.47%
- Veröffentlicht 21.01.2020 23:15:13
- Zuletzt bearbeitet 03.12.2025 16:15:54
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
CVE-2019-20388
- EPSS 0.56%
- Veröffentlicht 21.01.2020 23:15:13
- Zuletzt bearbeitet 21.11.2024 04:38:21
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
CVE-2019-19956
- EPSS 0.15%
- Veröffentlicht 24.12.2019 16:15:11
- Zuletzt bearbeitet 03.12.2025 19:15:50
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
CVE-2017-15412
- EPSS 3.55%
- Veröffentlicht 28.08.2018 19:29:05
- Zuletzt bearbeitet 21.11.2024 03:14:39
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.