Skip to main content

Vendor archive

xmlsoft CVEs

Beta · best-effort

136 CVEs tagged to vendor xmlsoft17 Critical, 52 High, 59 Medium, 8 Low, 0 Unrated.

CVE-2016-1684

Published Jun 5, 2016

numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denia…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-1683

Published Jun 5, 2016

numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bo…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-1840

Published May 20, 2016

Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS b…

CVSS 7.8 · High

CVE-2016-1839

Published May 20, 2016

The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers…

CVSS 5.5 · Medium

CVE-2016-1838

Published May 20, 2016

The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows…

CVSS 5.5 · Medium

CVE-2016-1837

Published May 20, 2016

Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X b…

CVSS 5.5 · Medium

CVE-2016-1836

Published May 20, 2016

Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS…

CVSS 5.5 · Medium

CVE-2016-1834

Published May 20, 2016

Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1,…

CVSS 7.8 · High

CVE-2016-1833

Published May 20, 2016

The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers…

CVSS 5.5 · Medium

CVE-2016-3627

Published May 17, 2016

The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite rec…

CVSS 7.5 · High

CVE-2015-6838

Published May 16, 2016

The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before 2.9.2 is used, does not consid…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6837

Published May 16, 2016

The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before 2.9.2 is used, does not consid…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8710

Published Apr 11, 2016

The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and applicat…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-8317

Published Dec 15, 2015

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) i…

CVSS 5.0 · Medium

CVE-2015-8242

Published Dec 15, 2015

The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-base…

CVSS 5.8 · Medium

CVE-2015-8241

Published Dec 15, 2015

The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and…

CVSS 6.4 · Medium

CVE-2015-7500

Published Dec 15, 2015

The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors rel…

CVSS 5.0 · Medium
Showing 76-100 of 136 CVEsPage 4 of 6