CVEs (25)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Redhat Xmlsoft3Enterprise Linux LibxsltOpenshift Container PlatformJun 29, 2026 Jul 10, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to cras...Show more |
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate,...Show more |
xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes. |
5Debian FedoraprojectNetapp+2 more19Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+16 moreJun 17, 2026 May 3, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to...Show more |
4Debian GoogleSplunk+1 more4Chrome Debian LinuxLibxslt+1 moreJun 17, 2026 Aug 3, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Debian Xmlsoft2Debian Linux LibxsltJun 17, 2026 Dec 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data. |
3Canonical DebianXmlsoft3Debian Linux LibxsltUbuntu LinuxJun 17, 2026 Oct 18, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and me...Show more |
7Apple CanonicalFedoraproject+4 more25Active Iq Unified Manager Cloud BackupClustered Data Ontap+22 moreJun 17, 2026 Jul 1, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Jul 1, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains...Show more |
7Canonical DebianFedoraproject+4 more22Active Iq Unified Manager Cloud BackupDebian Linux+19 moreJun 17, 2026 Apr 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is...Show more |
4Debian GoogleRedhat+1 more6Chrome Debian LinuxEnterprise Linux Desktop+3 moreMay 13, 2026 Apr 24, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow duri...Show more |
In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs. |
4Apple DebianFedoraproject+1 more5Debian Linux FedoraIcloud+2 moreMay 6, 2026 Jul 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (m...Show more |
4Apple DebianFedoraproject+1 more9Debian Linux FedoraIcloud+6 moreMay 6, 2026 Jul 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (m...Show more |
3Apple FedoraprojectXmlsoft4Fedora IcloudItunes+1 moreMay 6, 2026 Jul 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (m...Show more |
3Apple FedoraprojectXmlsoft8Fedora IcloudIphone Os+5 moreMay 6, 2026 Jul 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (m...Show more |
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resourc...Show more |
7Canonical DebianGoogle+4 more10Chrome Debian LinuxEnterprise Linux Desktop+7 moreMay 6, 2026 Jun 5, 2016 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bounds heap memory access) or possibly have...Show more |
2Apple Xmlsoft5Iphone Os LibxsltMac Os X+2 moreMay 6, 2026 Nov 17, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" i...Show more |
xslt.c in libxslt before 1.1.25 allows context-dependent attackers to cause a denial of service (crash) via a stylesheet that embeds a DTD, which causes a structure to be accessed as a different type. NOTE: this issue i...Show more |