Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2026-11979
libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function proce…
Libxml2
after 2.15.3
CRITICAL 9.8
CVE-2026-6653
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service …
Libxml2
after 2.11.0
MEDIUM 5.5
CVE-2025-9714
Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafte…
Libxml2
2.10.0+
HIGH 7.5
CVE-2025-32415
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a …
Libxml2
2.13.8 / 2.14.2+
HIGH 7.5
CVE-2025-32414
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect …
Libxml2
2.13.8 / 2.14.2+
HIGH 7.8
CVE-2024-55549
xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes.
Libxslt
1.1.43+
HIGH 7.8
CVE-2025-24855
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restore…
Libxslt
1.1.43+
HIGH 7.5
CVE-2025-27113
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
Libxml2
2.12.10 / 2.13.6+
CRITICAL 9.8
CVE-2024-56171
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. …
Libxml2
2.12.10 / 2.13.6+
HIGH 7.8
CVE-2022-49043
xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.
Libxml2
2.11.0+
CRITICAL 9.1
CVE-2024-40896
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX…
Libxml2
2.11.9 / 2.12.9+
HIGH 7.5
CVE-2024-34459
An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result…
Libxml2
2.11.8 / 2.12.7+
HIGH 7.5
CVE-2024-25062
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expan…
Libxml2
2.11.7 / 2.12.5+
MEDIUM 6.5
CVE-2023-45322
libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE…
Libxml2
after 2.11.5
MEDIUM 6.5
CVE-2023-39615
Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability…
Libxml2
Patch available
HIGH 7.8
CVE-2022-40304EPSS 7%
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequ…
Libxml2
2.10.3+
HIGH 7.5
CVE-2022-40303EPSS 23%
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several i…
Libxml2
2.10.3 / 15.7.2+
MEDIUM 6.1
CVE-2016-3709
Possible cross-site scripting vulnerability in libxml after commit 960f0e2.
Libxml2
2.9.11+
MEDIUM 6.5
CVE-2017-18258
The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA …
Libxml2
2.9.6+
CRITICAL 9.8
CVE-2017-16931
parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the …
Libxml2
after 2.9.4
HIGH 7.5
CVE-2017-16932EPSS 6%
parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
Libxml2
after 2.9.4
HIGH 7.5
CVE-2017-9047
A buffer overflow was discovered in libxml2 20904-GITv2.9.4-16-g0741801. The function xmlSnprintfElementContent in valid.c is supposed to recursively…
Libxml2
Patch available
HIGH 7.5
CVE-2017-9048
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to …
Libxml2
Patch available
HIGH 7.5
CVE-2017-9049
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerabilit…
Libxml2
Patch available
HIGH 7.5
CVE-2017-9050
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability cau…
Libxml2
Patch available
CRITICAL 9.1
CVE-2017-8872
The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information di…
Libxml2
Mitigation only
MEDIUM 5.3
CVE-2015-9019
In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this …
Libxslt
after 1.1.29
HIGH 7.5
CVE-2013-1969
Multiple use-after-free vulnerabilities in libxml2 2.9.0 and possibly other versions might allow context-dependent attackers to cause a denial of ser…
Libxml2
No fix yet
MEDIUM 5.0
CVE-2012-6139
libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a…
Libxslt
after 1.1.27
MEDIUM 5.0
CVE-2012-0841
libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent atta…
Libxml2
after 6.1.4