CVE-2016-9318
- EPSS 0.16%
- Veröffentlicht 16.11.2016 00:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to condu...
- EPSS 11.27%
- Veröffentlicht 25.09.2016 10:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary co...
CVE-2016-5131
- EPSS 3.69%
- Veröffentlicht 23.07.2016 19:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
CVE-2016-4449
- EPSS 0.12%
- Veröffentlicht 09.06.2016 16:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource con...
- EPSS 1.55%
- Veröffentlicht 09.06.2016 16:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
CVE-2016-4447
- EPSS 2.66%
- Veröffentlicht 09.06.2016 16:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.
CVE-2016-1840
- EPSS 1.59%
- Veröffentlicht 20.05.2016 10:59:54
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause...
CVE-2016-1839
- EPSS 4.55%
- Veröffentlicht 20.05.2016 10:59:53
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a craft...
CVE-2016-1838
- EPSS 3.49%
- Veröffentlicht 20.05.2016 10:59:52
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-...
CVE-2016-1837
- EPSS 0.52%
- Veröffentlicht 20.05.2016 10:59:51
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remot...