Xmlsoft

Libxml2

97 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.44%
  • Published 18.05.2017 06:29:00
  • Last modified 20.04.2025 01:37:25

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an in...

Exploit
  • EPSS 0.58%
  • Published 18.05.2017 06:29:00
  • Last modified 20.04.2025 01:37:25

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. At the end o...

Exploit
  • EPSS 2.79%
  • Published 18.05.2017 06:29:00
  • Last modified 20.04.2025 01:37:25

A buffer overflow was discovered in libxml2 20904-GITv2.9.4-16-g0741801. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. The variable len is ass...

  • EPSS 0.18%
  • Published 10.05.2017 05:29:00
  • Last modified 20.04.2025 01:37:25

The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure.

  • EPSS 2.71%
  • Published 11.04.2017 16:59:00
  • Last modified 20.04.2025 01:37:25

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should...

Exploit
  • EPSS 1.27%
  • Published 11.04.2017 16:59:00
  • Last modified 20.04.2025 01:37:25

The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE: this vulne...

Exploit
  • EPSS 0.04%
  • Published 16.11.2016 00:59:00
  • Last modified 12.04.2025 10:46:40

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to condu...

  • EPSS 19.34%
  • Published 25.09.2016 10:59:02
  • Last modified 12.04.2025 10:46:40

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary co...

  • EPSS 4.2%
  • Published 23.07.2016 19:59:13
  • Last modified 12.04.2025 10:46:40

Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.

  • EPSS 0.12%
  • Published 09.06.2016 16:59:07
  • Last modified 12.04.2025 10:46:40

XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource con...