CVE-2016-1836
- EPSS 1.31%
- Veröffentlicht 20.05.2016 10:59:50
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via ...
CVE-2016-1834
- EPSS 2.31%
- Veröffentlicht 20.05.2016 10:59:48
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of...
CVE-2016-1833
- EPSS 0.4%
- Veröffentlicht 20.05.2016 10:59:47
- Zuletzt bearbeitet 06.05.2026 22:30:45
The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafte...
CVE-2016-3705
- EPSS 0.88%
- Veröffentlicht 17.05.2016 14:08:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and applic...
CVE-2016-3627
- EPSS 0.09%
- Veröffentlicht 17.05.2016 14:08:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML doc...
CVE-2015-6838
- EPSS 3.8%
- Veröffentlicht 16.05.2016 10:59:21
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before 2.9.2 is used, does not consider the possibility of a NULL valuePop return value before proceeding wi...
CVE-2015-6837
- EPSS 3.8%
- Veröffentlicht 16.05.2016 10:59:20
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before 2.9.2 is used, does not consider the possibility of a NULL valuePop return value before proceeding wi...
CVE-2015-8806
- EPSS 8.57%
- Veröffentlicht 13.04.2016 17:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.
CVE-2015-8710
- EPSS 4.71%
- Veröffentlicht 11.04.2016 21:59:15
- Zuletzt bearbeitet 06.05.2026 22:30:45
The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed H...
CVE-2016-1762
- EPSS 2.42%
- Veröffentlicht 24.03.2016 01:59:30
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.