Записи xmlsoft
144 опубликованных записей вендора xmlsoft.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 10
- С записью об исправлении
- 97,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer33
- CWE-416 Use After Free17
- CWE-125 Out-of-bounds Read10
- CWE-399 Resource Management Errors8
- CWE-476 NULL Pointer Dereference6
- CWE-787 Out-of-bounds Write5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
144 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2008-3529Proof of concept | Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers toxmlsoft · libxml2 · CWE-119 | Критическая10,0 | — | 23,4 % | 12 сент. 2008 г. |
47В плане | CVE-2004-0989Proof of concept | Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrarxmlsoft · libxml | Критическая10,0 | — | 21,7 % | 1 мар. 2005 г. |
46В плане | CVE-2017-7376Proof of concept | Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling xmlsoft · libxml2 · CWE-119 | Критическая9,8 | — | 23,3 % | 19 февр. 2018 г. |
42В плане | CVE-2022-40303Эксплойта нет | An issue was discovered in libxml2 before 2.10.3.xmlsoft · libxml2 · CWE-190 | Высокая7,5 | — | 41,4 % | 22 нояб. 2022 г. |
42В плане | CVE-2021-3518Эксплойта нет | There's a flaw in libxml2 in versions before 2.9.11.xmlsoft · libxml2 · CWE-416 | Высокая8,8 | — | 21,9 % | 18 мая 2021 г. |
42В плане | CVE-2016-4658Эксплойта нет | xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other produapple · iphone os · CWE-119 | Критическая9,8 | — | 8,6 % | 25 сент. 2016 г. |
41В плане | CVE-2011-1944Proof of concept | Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependentxmlsoft · libxml2 · CWE-189 | Критическая9,3 | — | 13,4 % | 2 сент. 2011 г. |
41В плане | CVE-2016-4448Эксплойта нет | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vecthp · icewall federation agent · CWE-134 | Критическая9,8 | — | 7,0 % | 9 июн. 2016 г. |
41В плане | CVE-2019-11068Эксплойта нет | libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon rxmlsoft · libxslt | Критическая9,8 | — | 5,2 % | 10 апр. 2019 г. |
41В плане | CVE-2016-4609Эксплойта нет | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, apple · iphone os · CWE-119 | Критическая9,8 | — | 5,1 % | 21 июл. 2016 г. |
41В плане | CVE-2016-4610Эксплойта нет | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, apple · iphone os · CWE-119 | Критическая9,8 | — | 5,1 % | 21 июл. 2016 г. |
41В плане | CVE-2016-4607Эксплойта нет | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, apple · iphone os · CWE-119 | Критическая9,8 | — | 5,1 % | 21 июл. 2016 г. |
41В плане | CVE-2016-4608Эксплойта нет | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, apple · iphone os · CWE-119 | Критическая9,8 | — | 5,1 % | 21 июл. 2016 г. |
41В плане | CVE-2008-4226Эксплойта нет | Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory xmlsoft · libxml · CWE-399 | Критическая10,0 | — | 4,1 % | 25 нояб. 2008 г. |
40В плане | CVE-2021-30560Эксплойта нет | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a google · chrome · CWE-416 | Высокая8,8 | — | 17,6 % | 3 авг. 2021 г. |
40В плане | CVE-2015-8710Proof of concept | The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-ofxmlsoft · libxml2 · CWE-119 | Критическая9,8 | — | 4,9 % | 11 апр. 2016 г. |
40В плане | CVE-2017-16931Эксплойта нет | parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference functioxmlsoft · libxml2 · CWE-119 | Критическая9,8 | — | 4,3 % | 23 нояб. 2017 г. |
40В плане | CVE-2017-7375Эксплойта нет | A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, Dxmlsoft · libxml2 · CWE-611 | Критическая9,8 | — | 2,6 % | 19 февр. 2018 г. |
39Наблюдать | CVE-2021-3517Эксплойта нет | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11.xmlsoft · libxml2 · CWE-787 | Высокая8,6 | — | 17,0 % | 19 мая 2021 г. |
39Наблюдать | CVE-2024-56171Эксплойта нет | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlscxmlsoft · libxml2 · CWE-416 | Критическая9,8 | — | 1,2 % | 18 февр. 2025 г. |
37Наблюдать | CVE-2004-0110Proof of concept | Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execuxmlsoft · libxml | Высокая7,5 | — | 24,2 % | 15 мар. 2004 г. |
37Наблюдать | CVE-2017-8872Эксплойта нет | The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or inforxmlsoft · libxml2 · CWE-125 | Критическая9,1 | — | 2,3 % | 10 мая 2017 г. |
36Наблюдать | CVE-2017-15412Эксплойта нет | Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potegoogle · chrome · CWE-416 | Высокая8,8 | — | 2,9 % | 28 авг. 2018 г. |
36Наблюдать | CVE-2017-5130Эксплойта нет | An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remgoogle · chrome · CWE-787 | Высокая8,8 | — | 2,7 % | 7 февр. 2018 г. |
36Наблюдать | CVE-2016-5131Эксплойта нет | Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denigoogle · chrome · CWE-416 | Высокая8,8 | — | 2,3 % | 23 июл. 2016 г. |
- CVE-2008-352947В плане
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to
КритическаяCVSS 10,0Proof of conceptEPSS 23 %xmlsoft · libxml212 сент. 2008 г.
- CVE-2004-098947В плане
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrar
КритическаяCVSS 10,0Proof of conceptEPSS 22 %xmlsoft · libxml1 мар. 2005 г.
- CVE-2017-737646В плане
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling
КритическаяCVSS 9,8Proof of conceptEPSS 23 %xmlsoft · libxml219 февр. 2018 г.
- CVE-2022-4030342В плане
An issue was discovered in libxml2 before 2.10.3.
ВысокаяCVSS 7,5Эксплойта нетEPSS 41 %xmlsoft · libxml222 нояб. 2022 г.
- CVE-2021-351842В плане
There's a flaw in libxml2 in versions before 2.9.11.
ВысокаяCVSS 8,8Эксплойта нетEPSS 22 %xmlsoft · libxml218 мая 2021 г.
- CVE-2016-465842В плане
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other produ
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %apple · iphone os25 сент. 2016 г.
- CVE-2011-194441В плане
Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent
КритическаяCVSS 9,3Proof of conceptEPSS 13 %xmlsoft · libxml22 сент. 2011 г.
- CVE-2016-444841В плане
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vect
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %hp · icewall federation agent9 июн. 2016 г.
- CVE-2019-1106841В плане
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon r
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %xmlsoft · libxslt10 апр. 2019 г.
- CVE-2016-460941В плане
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %apple · iphone os21 июл. 2016 г.
- CVE-2016-461041В плане
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %apple · iphone os21 июл. 2016 г.
- CVE-2016-460741В плане
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %apple · iphone os21 июл. 2016 г.
- CVE-2016-460841В плане
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %apple · iphone os21 июл. 2016 г.
- CVE-2008-422641В плане
Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %xmlsoft · libxml25 нояб. 2008 г.
- CVE-2021-3056040В плане
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a
ВысокаяCVSS 8,8Эксплойта нетEPSS 18 %google · chrome3 авг. 2021 г.
- CVE-2015-871040В плане
The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of
КритическаяCVSS 9,8Proof of conceptEPSS 5 %xmlsoft · libxml211 апр. 2016 г.
- CVE-2017-1693140В плане
parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference functio
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %xmlsoft · libxml223 нояб. 2017 г.
- CVE-2017-737540В плане
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, D
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %xmlsoft · libxml219 февр. 2018 г.
- CVE-2021-351739Наблюдать
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11.
ВысокаяCVSS 8,6Эксплойта нетEPSS 17 %xmlsoft · libxml219 мая 2021 г.
- CVE-2024-5617139Наблюдать
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlsc
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %xmlsoft · libxml218 февр. 2025 г.
- CVE-2004-011037Наблюдать
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execu
ВысокаяCVSS 7,5Proof of conceptEPSS 24 %xmlsoft · libxml15 мар. 2004 г.
- CVE-2017-887237Наблюдать
The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or infor
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %xmlsoft · libxml210 мая 2017 г.
- CVE-2017-1541236Наблюдать
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to pote
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %google · chrome28 авг. 2018 г.
- CVE-2017-513036Наблюдать
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a rem
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %google · chrome7 февр. 2018 г.
- CVE-2016-513136Наблюдать
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a deni
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %google · chrome23 июл. 2016 г.