Vulnerability index

Browse CVEs

36 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-11979 libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function proce… Libxml2 after 2.15.3 Fix from $1,9502026-06-29 CRITICAL 9.8 CVE-2026-6653 Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service … Libxml2 after 2.11.0 Fix from $2,3002026-06-22 MEDIUM 5.5 CVE-2025-9714 Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafte… Libxml2 2.10.0+ Fix from $1,6002025-09-10 HIGH 7.5 CVE-2025-32415 In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a … Libxml2 2.13.8 / 2.14.2+ Fix from $1,9502025-04-17 HIGH 7.5 CVE-2025-32414 In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect … Libxml2 2.13.8 / 2.14.2+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2024-55549 xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes. Libxslt 1.1.43+ Fix from $1,9502025-03-14 HIGH 7.8 CVE-2025-24855 numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restore… Libxslt 1.1.43+ Fix from $1,9502025-03-14 HIGH 7.5 CVE-2025-27113 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c. Libxml2 2.12.10 / 2.13.6+ Fix from $1,9502025-02-18 CRITICAL 9.8 CVE-2024-56171 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. … Libxml2 2.12.10 / 2.13.6+ Fix from $2,3002025-02-18 HIGH 7.8 CVE-2022-49043 xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free. Libxml2 2.11.0+ Fix from $1,9502025-01-26 CRITICAL 9.1 CVE-2024-40896 In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX… Libxml2 2.11.9 / 2.12.9+ Fix from $2,3002024-12-23 HIGH 7.5 CVE-2024-34459 An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result… Libxml2 2.11.8 / 2.12.7+ Fix from $1,9502024-05-14 HIGH 7.5 CVE-2024-25062 An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expan… Libxml2 2.11.7 / 2.12.5+ Fix from $1,9502024-02-04 MEDIUM 6.5 CVE-2023-45322 libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE… Libxml2 after 2.11.5 Fix from $1,6002023-10-06 MEDIUM 6.5 CVE-2023-39615 Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability… Libxml2 Patch available Fix from $1,6002023-08-29 HIGH 7.8 CVE-2022-40304EPSS 7% An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequ… Libxml2 2.10.3+ Fix from $1,9502022-11-23 HIGH 7.5 CVE-2022-40303EPSS 23% An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several i… Libxml2 2.10.3 / 15.7.2+ Fix from $1,9502022-11-23 MEDIUM 6.1 CVE-2016-3709 Possible cross-site scripting vulnerability in libxml after commit 960f0e2. Libxml2 2.9.11+ Fix from $1,6002022-07-28 MEDIUM 6.5 CVE-2017-18258 The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA … Libxml2 2.9.6+ Fix from $1,6002018-04-08 CRITICAL 9.8 CVE-2017-16931 parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the … Libxml2 after 2.9.4 Fix from $2,3002017-11-23 HIGH 7.5 CVE-2017-16932EPSS 6% parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities. Libxml2 after 2.9.4 Fix from $1,9502017-11-23 HIGH 7.5 CVE-2017-9047 A buffer overflow was discovered in libxml2 20904-GITv2.9.4-16-g0741801. The function xmlSnprintfElementContent in valid.c is supposed to recursively… Libxml2 Patch available Fix from $1,9502017-05-18 HIGH 7.5 CVE-2017-9048 libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to … Libxml2 Patch available Fix from $1,9502017-05-18 HIGH 7.5 CVE-2017-9049 libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerabilit… Libxml2 Patch available Fix from $1,9502017-05-18 HIGH 7.5 CVE-2017-9050 libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability cau… Libxml2 Patch available Fix from $1,9502017-05-18 CRITICAL 9.1 CVE-2017-8872 The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information di… Libxml2 Mitigation only Fix from $2,3002017-05-10 MEDIUM 5.3 CVE-2015-9019 In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this … Libxslt after 1.1.29 Fix from $1,6002017-04-05 HIGH 7.5 CVE-2013-1969 Multiple use-after-free vulnerabilities in libxml2 2.9.0 and possibly other versions might allow context-dependent attackers to cause a denial of ser… Libxml2 No fix yet Fix from $1,9502013-04-25 MEDIUM 5.0 CVE-2012-6139 libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a… Libxslt after 1.1.27 Fix from $1,6002013-04-12 MEDIUM 5.0 CVE-2012-0841 libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent atta… Libxml2 after 6.1.4 Fix from $1,6002012-12-21