Skip to main content

Vendor archive

xmlsoft CVEs

Beta · best-effort

136 CVEs tagged to vendor xmlsoft17 Critical, 52 High, 59 Medium, 8 Low, 0 Unrated.

CVE-2016-9596

Published Aug 16, 2018

libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack consumption) via a crafted XML do…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18258

Published Apr 8, 2018

The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder func…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9251

Published Apr 4, 2018

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that trigge…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16932

Published Nov 23, 2017

parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16931

Published Nov 23, 2017

parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a D…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-9050

Published May 18, 2017

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9049

Published May 18, 2017

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use lib…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9048

Published May 18, 2017

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9047

Published May 18, 2017

A buffer overflow was discovered in libxml2 20904-GITv2.9.4-16-g0741801. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content defi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8872

Published May 10, 2017

The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-5029

Published Apr 24, 2017

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android,…

CVSS 8.8 · High

CVE-2017-5969

Published Apr 11, 2017

libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-9019

Published Apr 5, 2017

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictabl…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5131

Published Jul 23, 2016

Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecif…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Showing 51-75 of 136 CVEsPage 3 of 6