Skip to main content

Vendor/product archive

xmlsoft / libxml2 CVEs

Beta · best-effort

108 CVEs tagged to xmlsoft / libxml211 Critical, 40 High, 49 Medium, 8 Low, 0 Unrated.

CVE-2026-11979

Published Jun 29, 2026

libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-si…

CVSS 1.8 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-6653

Published Jun 22, 2026

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML in…

CVSS 7.0 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-9714

Published Sep 10, 2025

Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processin…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32415

Published Apr 17, 2025

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be v…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-32414

Published Apr 8, 2025

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in x…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27113

Published Feb 18, 2025

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-24928

Published Feb 18, 2025

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted do…

CVSS 7.8 · High

CVE-2024-56171

Published Feb 18, 2025

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML…

CVSS 7.8 · High

CVE-2022-49043

Published Jan 26, 2025

xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-40896

Published Dec 23, 2024

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override enti…

CVSS 9.1 · Critical

CVE-2024-34459

Published May 14, 2024

An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlH…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25062

Published Feb 4, 2024

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing craft…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45322

Published Oct 6, 2023

libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39615

Published Aug 29, 2023

Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a D…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29469

Published Apr 24, 2023

An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28484

Published Apr 24, 2023

In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xm…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 108 CVEsPage 1 of 5