Xmlsoft

Libxml2

100 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 13.74%
  • Veröffentlicht 23.11.2017 21:29:00
  • Zuletzt bearbeitet 04.12.2025 14:16:01

parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.

  • EPSS 1.27%
  • Veröffentlicht 23.11.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name.

Exploit
  • EPSS 0.36%
  • Veröffentlicht 18.05.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incompl...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 18.05.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an in...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 18.05.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. At the end o...

Exploit
  • EPSS 3.02%
  • Veröffentlicht 18.05.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A buffer overflow was discovered in libxml2 20904-GITv2.9.4-16-g0741801. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. The variable len is ass...

  • EPSS 0.2%
  • Veröffentlicht 10.05.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure.

  • EPSS 2.71%
  • Veröffentlicht 11.04.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should...

Exploit
  • EPSS 0.94%
  • Veröffentlicht 11.04.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE: this vulne...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 16.11.2016 00:59:00
  • Zuletzt bearbeitet 04.12.2025 17:15:51

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to condu...