CVEs (107)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds ch...Show more |
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handl...Show more |
3Ibm RedhatXmlsoft7Aix Enterprise LinuxHardened Images+4 moreJun 30, 2026 Apr 23, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit t...Show more |
3Ibm RedhatXmlsoft7Aix Enterprise LinuxHardened Images+4 moreJun 30, 2026 Jan 15, 2026 N/A· v4 2.9 LOW· v3 N/A· v2 A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A re...Show more |
3Ibm RedhatXmlsoft7Aix Enterprise LinuxHardened Images+4 moreJun 30, 2026 Jan 15, 2026 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A re...Show more |
3Ibm RedhatXmlsoft7Aix Enterprise LinuxHardened Images+4 moreJun 30, 2026 Jan 15, 2026 N/A· v4 3.7 LOW· v3 N/A· v2 A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially c...Show more |
Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathC...Show more |
3Ibm SiemensXmlsoft4Aix Libxml2Ruggedcom Rst2428p Firmware+1 moreJul 1, 2026 Aug 8, 2025 1.9 LOW· v4 3.3 LOW· v3 1.7 LOW· v2 A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recu...Show more |
2Redhat Xmlsoft4Enterprise Linux Jboss Core ServicesLibxml2+1 moreJul 23, 2026 Jun 16, 2025 N/A· v4 2.5 LOW· v3 N/A· v2 A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to...Show more |
2Redhat Xmlsoft20Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+17 moreJun 30, 2026 Jun 12, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when...Show more |
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certa...Show more |
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw...Show more |
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c. |
2Netapp Xmlsoft11Active Iq Unified Manager H300s FirmwareH410c Firmware+8 moreJun 17, 2026 Feb 18, 2025 N/A· v4 7.7 HIGH· v3 N/A· v2 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is si...Show more |
2Netapp Xmlsoft11Active Iq Unified Manager H300s FirmwareH410c Firmware+8 moreJun 17, 2026 Feb 18, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XM...Show more |
xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free. |
2Netapp Xmlsoft9H300s Firmware H410c FirmwareH410s Firmware+6 moreJun 17, 2026 Dec 23, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This m...Show more |
An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c. |
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValida...Show more |
libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical eno...Show more |