Xmlsoft

Libxml2

100 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 19.34%
  • Veröffentlicht 25.09.2016 10:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary co...

  • EPSS 3.87%
  • Veröffentlicht 23.07.2016 19:59:13
  • Zuletzt bearbeitet 04.12.2025 17:15:49

Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.

  • EPSS 0.12%
  • Veröffentlicht 09.06.2016 16:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource con...

  • EPSS 1.2%
  • Veröffentlicht 09.06.2016 16:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.

Exploit
  • EPSS 3.33%
  • Veröffentlicht 09.06.2016 16:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.

Exploit
  • EPSS 2.14%
  • Veröffentlicht 20.05.2016 10:59:54
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause...

Exploit
  • EPSS 10.77%
  • Veröffentlicht 20.05.2016 10:59:53
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a craft...

Exploit
  • EPSS 10.65%
  • Veröffentlicht 20.05.2016 10:59:52
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-...

Exploit
  • EPSS 0.79%
  • Veröffentlicht 20.05.2016 10:59:51
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remot...

  • EPSS 1.15%
  • Veröffentlicht 20.05.2016 10:59:50
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via ...