xmlsoft records
144 published records for vendor xmlsoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 10
- With a fix record
- 97.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer33
- CWE-416 Use After Free17
- CWE-125 Out-of-bounds Read10
- CWE-399 Resource Management Errors8
- CWE-476 NULL Pointer Dereference6
- CWE-787 Out-of-bounds Write5
The weakness classes this vendor ships most often: where to look.
CWEAll records
144 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2008-3529Proof of concept | Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers toxmlsoft · libxml2 · CWE-119 | Critical10.0 | — | 23.4% | Sep 12, 2008 |
47Plan | CVE-2004-0989Proof of concept | Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrarxmlsoft · libxml | Critical10.0 | — | 21.7% | Mar 1, 2005 |
46Plan | CVE-2017-7376Proof of concept | Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling xmlsoft · libxml2 · CWE-119 | Critical9.8 | — | 23.3% | Feb 19, 2018 |
42Plan | CVE-2022-40303No exploit | An issue was discovered in libxml2 before 2.10.3.xmlsoft · libxml2 · CWE-190 | High7.5 | — | 41.4% | Nov 22, 2022 |
42Plan | CVE-2021-3518No exploit | There's a flaw in libxml2 in versions before 2.9.11.xmlsoft · libxml2 · CWE-416 | High8.8 | — | 21.9% | May 18, 2021 |
42Plan | CVE-2016-4658No exploit | xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other produapple · iphone os · CWE-119 | Critical9.8 | — | 8.6% | Sep 25, 2016 |
41Plan | CVE-2011-1944Proof of concept | Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependentxmlsoft · libxml2 · CWE-189 | Critical9.3 | — | 13.4% | Sep 2, 2011 |
41Plan | CVE-2016-4448No exploit | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vecthp · icewall federation agent · CWE-134 | Critical9.8 | — | 7.0% | Jun 9, 2016 |
41Plan | CVE-2019-11068No exploit | libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon rxmlsoft · libxslt | Critical9.8 | — | 5.2% | Apr 10, 2019 |
41Plan | CVE-2016-4609No exploit | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, apple · iphone os · CWE-119 | Critical9.8 | — | 5.1% | Jul 21, 2016 |
41Plan | CVE-2016-4610No exploit | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, apple · iphone os · CWE-119 | Critical9.8 | — | 5.1% | Jul 21, 2016 |
41Plan | CVE-2016-4607No exploit | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, apple · iphone os · CWE-119 | Critical9.8 | — | 5.1% | Jul 21, 2016 |
41Plan | CVE-2016-4608No exploit | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, apple · iphone os · CWE-119 | Critical9.8 | — | 5.1% | Jul 21, 2016 |
41Plan | CVE-2008-4226No exploit | Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory xmlsoft · libxml · CWE-399 | Critical10.0 | — | 4.1% | Nov 25, 2008 |
40Plan | CVE-2021-30560No exploit | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a google · chrome · CWE-416 | High8.8 | — | 17.6% | Aug 3, 2021 |
40Plan | CVE-2015-8710Proof of concept | The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-ofxmlsoft · libxml2 · CWE-119 | Critical9.8 | — | 4.9% | Apr 11, 2016 |
40Plan | CVE-2017-16931No exploit | parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference functioxmlsoft · libxml2 · CWE-119 | Critical9.8 | — | 4.3% | Nov 23, 2017 |
40Plan | CVE-2017-7375No exploit | A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, Dxmlsoft · libxml2 · CWE-611 | Critical9.8 | — | 2.6% | Feb 19, 2018 |
39Monitor | CVE-2021-3517No exploit | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11.xmlsoft · libxml2 · CWE-787 | High8.6 | — | 17.0% | May 19, 2021 |
39Monitor | CVE-2024-56171No exploit | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlscxmlsoft · libxml2 · CWE-416 | Critical9.8 | — | 1.2% | Feb 18, 2025 |
37Monitor | CVE-2004-0110Proof of concept | Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execuxmlsoft · libxml | High7.5 | — | 24.2% | Mar 15, 2004 |
37Monitor | CVE-2017-8872No exploit | The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or inforxmlsoft · libxml2 · CWE-125 | Critical9.1 | — | 2.3% | May 10, 2017 |
36Monitor | CVE-2017-15412No exploit | Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potegoogle · chrome · CWE-416 | High8.8 | — | 2.9% | Aug 28, 2018 |
36Monitor | CVE-2017-5130No exploit | An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remgoogle · chrome · CWE-787 | High8.8 | — | 2.7% | Feb 7, 2018 |
36Monitor | CVE-2016-5131No exploit | Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denigoogle · chrome · CWE-416 | High8.8 | — | 2.3% | Jul 23, 2016 |
- CVE-2008-352947Plan
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to
CriticalCVSS 10.0Proof of conceptEPSS 23%xmlsoft · libxml2Sep 12, 2008
- CVE-2004-098947Plan
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrar
CriticalCVSS 10.0Proof of conceptEPSS 22%xmlsoft · libxmlMar 1, 2005
- CVE-2017-737646Plan
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling
CriticalCVSS 9.8Proof of conceptEPSS 23%xmlsoft · libxml2Feb 19, 2018
- CVE-2022-4030342Plan
An issue was discovered in libxml2 before 2.10.3.
HighCVSS 7.5No exploitEPSS 41%xmlsoft · libxml2Nov 22, 2022
- CVE-2021-351842Plan
There's a flaw in libxml2 in versions before 2.9.11.
HighCVSS 8.8No exploitEPSS 22%xmlsoft · libxml2May 18, 2021
- CVE-2016-465842Plan
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other produ
CriticalCVSS 9.8No exploitEPSS 9%apple · iphone osSep 25, 2016
- CVE-2011-194441Plan
Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent
CriticalCVSS 9.3Proof of conceptEPSS 13%xmlsoft · libxml2Sep 2, 2011
- CVE-2016-444841Plan
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vect
CriticalCVSS 9.8No exploitEPSS 7%hp · icewall federation agentJun 9, 2016
- CVE-2019-1106841Plan
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon r
CriticalCVSS 9.8No exploitEPSS 5%xmlsoft · libxsltApr 10, 2019
- CVE-2016-460941Plan
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,
CriticalCVSS 9.8No exploitEPSS 5%apple · iphone osJul 21, 2016
- CVE-2016-461041Plan
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,
CriticalCVSS 9.8No exploitEPSS 5%apple · iphone osJul 21, 2016
- CVE-2016-460741Plan
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,
CriticalCVSS 9.8No exploitEPSS 5%apple · iphone osJul 21, 2016
- CVE-2016-460841Plan
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,
CriticalCVSS 9.8No exploitEPSS 5%apple · iphone osJul 21, 2016
- CVE-2008-422641Plan
Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory
CriticalCVSS 10.0No exploitEPSS 4%xmlsoft · libxmlNov 25, 2008
- CVE-2021-3056040Plan
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a
HighCVSS 8.8No exploitEPSS 18%google · chromeAug 3, 2021
- CVE-2015-871040Plan
The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of
CriticalCVSS 9.8Proof of conceptEPSS 5%xmlsoft · libxml2Apr 11, 2016
- CVE-2017-1693140Plan
parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference functio
CriticalCVSS 9.8No exploitEPSS 4%xmlsoft · libxml2Nov 23, 2017
- CVE-2017-737540Plan
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, D
CriticalCVSS 9.8No exploitEPSS 3%xmlsoft · libxml2Feb 19, 2018
- CVE-2021-351739Monitor
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11.
HighCVSS 8.6No exploitEPSS 17%xmlsoft · libxml2May 19, 2021
- CVE-2024-5617139Monitor
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlsc
CriticalCVSS 9.8No exploitEPSS 1%xmlsoft · libxml2Feb 18, 2025
- CVE-2004-011037Monitor
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execu
HighCVSS 7.5Proof of conceptEPSS 24%xmlsoft · libxmlMar 15, 2004
- CVE-2017-887237Monitor
The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or infor
CriticalCVSS 9.1No exploitEPSS 2%xmlsoft · libxml2May 10, 2017
- CVE-2017-1541236Monitor
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to pote
HighCVSS 8.8No exploitEPSS 3%google · chromeAug 28, 2018
- CVE-2017-513036Monitor
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a rem
HighCVSS 8.8No exploitEPSS 3%google · chromeFeb 7, 2018
- CVE-2016-513136Monitor
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a deni
HighCVSS 8.8No exploitEPSS 2%google · chromeJul 23, 2016