CVE-2016-1839
- EPSS 10.77%
- Veröffentlicht 20.05.2016 10:59:53
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a craft...
CVE-2016-1838
- EPSS 10.65%
- Veröffentlicht 20.05.2016 10:59:52
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-...
CVE-2016-1837
- EPSS 0.79%
- Veröffentlicht 20.05.2016 10:59:51
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remot...
CVE-2016-1836
- EPSS 1.15%
- Veröffentlicht 20.05.2016 10:59:50
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via ...
CVE-2016-1835
- EPSS 2.57%
- Veröffentlicht 20.05.2016 10:59:49
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the xmlSAX2AttributeNs function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2 and OS X before 10.11.5, allows remote attackers to cause a denial of service via a crafted XML document.
CVE-2016-1834
- EPSS 2.37%
- Veröffentlicht 20.05.2016 10:59:48
- Zuletzt bearbeitet 04.12.2025 18:15:49
Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of...
CVE-2016-1833
- EPSS 1.21%
- Veröffentlicht 20.05.2016 10:59:47
- Zuletzt bearbeitet 12.04.2025 10:46:40
The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafte...
CVE-2016-3705
- EPSS 1.03%
- Veröffentlicht 17.05.2016 14:08:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and applic...
CVE-2016-3674
- EPSS 2.86%
- Veröffentlicht 17.05.2016 14:08:03
- Zuletzt bearbeitet 23.05.2025 17:54:18
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbi...
CVE-2016-3627
- EPSS 0.16%
- Veröffentlicht 17.05.2016 14:08:02
- Zuletzt bearbeitet 04.12.2025 17:15:48
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML doc...