- EPSS 1.2%
- Published 09.06.2016 16:59:06
- Last modified 12.04.2025 10:46:40
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
CVE-2016-4447
- EPSS 3.33%
- Published 09.06.2016 16:59:05
- Last modified 12.04.2025 10:46:40
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.
CVE-2016-1840
- EPSS 2.14%
- Published 20.05.2016 10:59:54
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause...
CVE-2016-1839
- EPSS 10.77%
- Published 20.05.2016 10:59:53
- Last modified 12.04.2025 10:46:40
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a craft...
CVE-2016-1838
- EPSS 10.65%
- Published 20.05.2016 10:59:52
- Last modified 12.04.2025 10:46:40
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-...
CVE-2016-1837
- EPSS 0.79%
- Published 20.05.2016 10:59:51
- Last modified 12.04.2025 10:46:40
Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remot...
CVE-2016-1836
- EPSS 1.15%
- Published 20.05.2016 10:59:50
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via ...
CVE-2016-1834
- EPSS 2.37%
- Published 20.05.2016 10:59:48
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of...
CVE-2016-1833
- EPSS 1.21%
- Published 20.05.2016 10:59:47
- Last modified 12.04.2025 10:46:40
The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafte...
CVE-2016-3705
- EPSS 1.03%
- Published 17.05.2016 14:08:04
- Last modified 12.04.2025 10:46:40
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and applic...