← Back

Xmlsoft

xmlsoft

135 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Libxml2
libxml2
Libxslt
libxslt
Libxml
libxml
Xmllint
xmllint

CVEs (135)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
DebianHp+2 more
9Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+6 more
May 6, 2026
Dec 15, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an...Show more
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.Show less
5Canonical
DebianHp+2 more
9Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+6 more
May 6, 2026
Dec 15, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.
6Apple
CanonicalDebian+3 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+10 more
May 6, 2026
Dec 15, 2015
N/A· v4
N/A· v3
7.1 HIGH· v2
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted...Show more
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.Show less
4Apple
CanonicalDebian+1 more
7Debian Linux
Iphone OsLibxml2+4 more
May 6, 2026
Nov 18, 2015
N/A· v4
N/A· v3
2.6 LOW· v2
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
5Apple
CanonicalDebian+2 more
9Debian Linux
Icewall Federation AgentIcewall File Manager+6 more
May 6, 2026
Nov 18, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out...Show more
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.Show less
2Canonical
Xmlsoft
2Libxml2
Ubuntu Linux
May 6, 2026
Nov 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl...Show more
libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.Show less
2Apple
Xmlsoft
5Iphone Os
LibxsltMac Os X+2 more
May 6, 2026
Nov 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" i...Show more
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.Show less
8Apple
CanonicalDebian+5 more
12Debian Linux
Enterprise LinuxFedora+9 more
May 6, 2026
Aug 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
5Apple
CanonicalDebian+2 more
5Debian Linux
Enterprise LinuxLibxml2+2 more
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a c...Show more
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.Show less
4Canonical
DebianSuse+1 more
4Debian Linux
Libxml2Linux Enterprise Server+1 more
Apr 29, 2026
Jan 21, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a de...Show more
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because libxml2 already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed and each affected application would need its own CVE.Show less
1Xmlsoft
1Libxslt
Apr 29, 2026
Dec 14, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
xslt.c in libxslt before 1.1.25 allows context-dependent attackers to cause a denial of service (crash) via a stylesheet that embeds a DTD, which causes a structure to be accessed as a different type. NOTE: this issue i...Show more
xslt.c in libxslt before 1.1.25 allows context-dependent attackers to cause a denial of service (crash) via a stylesheet that embeds a DTD, which causes a structure to be accessed as a different type. NOTE: this issue is due to an incomplete fix for CVE-2012-2825.Show less
2Google
Xmlsoft
2Chrome
Libxml2
Apr 29, 2026
Jul 10, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to t...Show more
parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state.Show less
1Xmlsoft
1Libxml2
Apr 29, 2026
Apr 25, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple use-after-free vulnerabilities in libxml2 2.9.0 and possibly other versions might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to...Show more
Multiple use-after-free vulnerabilities in libxml2 2.9.0 and possibly other versions might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to the (1) htmlParseChunk and (2) xmldecl_done functions, as demonstrated by a buffer overflow in the xmlBufGetInputBase function.Show less
3Canonical
OpensuseXmlsoft
3Libxml2
OpensuseUbuntu Linux
Apr 29, 2026
Apr 25, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to th...Show more
libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.Show less
2Opensuse
Xmlsoft
2Libxslt
Opensuse
Apr 29, 2026
Apr 12, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized vari...Show more
libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized variable to the xsltDocumentFunction function in functions.c.Show less
2Apple
Xmlsoft
2Iphone Os
Libxml2
Apr 29, 2026
Dec 21, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML da...Show more
libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.Show less
3Apple
GoogleXmlsoft
3Chrome
Iphone OsLibxml2
Apr 29, 2026
Nov 28, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of...Show more
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.Show less
3Apple
GoogleXmlsoft
3Chrome
Iphone OsLibxml2
Apr 29, 2026
Aug 31, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial...Show more
libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document, related to the _xmlNs data structure in include/libxml/tree.h.Show less
3Apple
GoogleXmlsoft
3Chrome
Iphone OsLibxslt
Apr 29, 2026
Aug 31, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression...Show more
libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/pattern.c and (2) the xsltGenerateIdFunction function in libxslt/functions.c.Show less
3Google
SuseXmlsoft
5Chrome
LibxsltLinux Enterprise Desktop+2 more
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.