Skip to content
Noroxi

xmlsoft records

144 published records for vendor xmlsoft.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
10
With a fix record
97.2%
Median publish → KEV
No record has entered KEV

All records

144 records
  • Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to

    CriticalCVSS 10.0Proof of conceptEPSS 23%

    xmlsoft · libxml2Sep 12, 2008

  • Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrar

    CriticalCVSS 10.0Proof of conceptEPSS 22%

    xmlsoft · libxmlMar 1, 2005

  • Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling

    CriticalCVSS 9.8Proof of conceptEPSS 23%

    xmlsoft · libxml2Feb 19, 2018

  • An issue was discovered in libxml2 before 2.10.3.

    HighCVSS 7.5No exploitEPSS 41%

    xmlsoft · libxml2Nov 22, 2022

  • There's a flaw in libxml2 in versions before 2.9.11.

    HighCVSS 8.8No exploitEPSS 22%

    xmlsoft · libxml2May 18, 2021

  • xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other produ

    CriticalCVSS 9.8No exploitEPSS 9%

    apple · iphone osSep 25, 2016

  • Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent

    CriticalCVSS 9.3Proof of conceptEPSS 13%

    xmlsoft · libxml2Sep 2, 2011

  • Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vect

    CriticalCVSS 9.8No exploitEPSS 7%

    hp · icewall federation agentJun 9, 2016

  • libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon r

    CriticalCVSS 9.8No exploitEPSS 5%

    xmlsoft · libxsltApr 10, 2019

  • libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,

    CriticalCVSS 9.8No exploitEPSS 5%

    apple · iphone osJul 21, 2016

  • libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,

    CriticalCVSS 9.8No exploitEPSS 5%

    apple · iphone osJul 21, 2016

  • libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,

    CriticalCVSS 9.8No exploitEPSS 5%

    apple · iphone osJul 21, 2016

  • libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,

    CriticalCVSS 9.8No exploitEPSS 5%

    apple · iphone osJul 21, 2016

  • Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory

    CriticalCVSS 10.0No exploitEPSS 4%

    xmlsoft · libxmlNov 25, 2008

  • Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a

    HighCVSS 8.8No exploitEPSS 18%

    google · chromeAug 3, 2021

  • The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    xmlsoft · libxml2Apr 11, 2016

  • parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference functio

    CriticalCVSS 9.8No exploitEPSS 4%

    xmlsoft · libxml2Nov 23, 2017

  • A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, D

    CriticalCVSS 9.8No exploitEPSS 3%

    xmlsoft · libxml2Feb 19, 2018

  • CVE-2021-3517
    39Monitor

    There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11.

    HighCVSS 8.6No exploitEPSS 17%

    xmlsoft · libxml2May 19, 2021

  • libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlsc

    CriticalCVSS 9.8No exploitEPSS 1%

    xmlsoft · libxml2Feb 18, 2025

  • CVE-2004-0110
    37Monitor

    Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execu

    HighCVSS 7.5Proof of conceptEPSS 24%

    xmlsoft · libxmlMar 15, 2004

  • CVE-2017-8872
    37Monitor

    The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or infor

    CriticalCVSS 9.1No exploitEPSS 2%

    xmlsoft · libxml2May 10, 2017

  • Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to pote

    HighCVSS 8.8No exploitEPSS 3%

    google · chromeAug 28, 2018

  • CVE-2017-5130
    36Monitor

    An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a rem

    HighCVSS 8.8No exploitEPSS 3%

    google · chromeFeb 7, 2018

  • CVE-2016-5131
    36Monitor

    Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a deni

    HighCVSS 8.8No exploitEPSS 2%

    google · chromeJul 23, 2016