Skip to main content

Vendor archive

xmlsoft CVEs

Beta · best-effort

136 CVEs tagged to vendor xmlsoft17 Critical, 52 High, 59 Medium, 8 Low, 0 Unrated.

CVE-2023-28484

Published Apr 24, 2023

In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xm…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3709

Published Jul 28, 2022

Possible cross-site scripting vulnerability in libxml after commit 960f0e2.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3516

Published Jun 1, 2021

There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The grea…

CVSS 7.8 · High

CVE-2019-5815

Published Dec 11, 2019

Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-9598

Published Aug 16, 2018

libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted XML docum…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 136 CVEsPage 2 of 6