xmlsoft kayıtları
xmlsoft üreticisine ait 144 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 10
- Düzeltme kaydı olan
- %97,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer33
- CWE-416 Use After Free17
- CWE-125 Out-of-bounds Read10
- CWE-399 Resource Management Errors8
- CWE-476 NULL Pointer Dereference6
- CWE-787 Out-of-bounds Write5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
144 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
47Planlayın | CVE-2008-3529Kavram kanıtı | Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers toxmlsoft · libxml2 · CWE-119 | Kritik10,0 | — | %23,4 | 12 Eyl 2008 |
47Planlayın | CVE-2004-0989Kavram kanıtı | Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrarxmlsoft · libxml | Kritik10,0 | — | %21,7 | 1 Mar 2005 |
46Planlayın | CVE-2017-7376Kavram kanıtı | Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling xmlsoft · libxml2 · CWE-119 | Kritik9,8 | — | %23,3 | 19 Şub 2018 |
42Planlayın | CVE-2022-40303İstismar yok | An issue was discovered in libxml2 before 2.10.3.xmlsoft · libxml2 · CWE-190 | Yüksek7,5 | — | %41,4 | 22 Kas 2022 |
42Planlayın | CVE-2021-3518İstismar yok | There's a flaw in libxml2 in versions before 2.9.11.xmlsoft · libxml2 · CWE-416 | Yüksek8,8 | — | %21,9 | 18 May 2021 |
42Planlayın | CVE-2016-4658İstismar yok | xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other produapple · iphone os · CWE-119 | Kritik9,8 | — | %8,6 | 25 Eyl 2016 |
41Planlayın | CVE-2011-1944Kavram kanıtı | Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependentxmlsoft · libxml2 · CWE-189 | Kritik9,3 | — | %13,4 | 2 Eyl 2011 |
41Planlayın | CVE-2016-4448İstismar yok | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vecthp · icewall federation agent · CWE-134 | Kritik9,8 | — | %7,0 | 9 Haz 2016 |
41Planlayın | CVE-2019-11068İstismar yok | libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon rxmlsoft · libxslt | Kritik9,8 | — | %5,2 | 10 Nis 2019 |
41Planlayın | CVE-2016-4609İstismar yok | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, apple · iphone os · CWE-119 | Kritik9,8 | — | %5,1 | 21 Tem 2016 |
41Planlayın | CVE-2016-4610İstismar yok | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, apple · iphone os · CWE-119 | Kritik9,8 | — | %5,1 | 21 Tem 2016 |
41Planlayın | CVE-2016-4607İstismar yok | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, apple · iphone os · CWE-119 | Kritik9,8 | — | %5,1 | 21 Tem 2016 |
41Planlayın | CVE-2016-4608İstismar yok | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, apple · iphone os · CWE-119 | Kritik9,8 | — | %5,1 | 21 Tem 2016 |
41Planlayın | CVE-2008-4226İstismar yok | Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory xmlsoft · libxml · CWE-399 | Kritik10,0 | — | %4,1 | 25 Kas 2008 |
40Planlayın | CVE-2021-30560İstismar yok | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a google · chrome · CWE-416 | Yüksek8,8 | — | %17,6 | 3 Ağu 2021 |
40Planlayın | CVE-2015-8710Kavram kanıtı | The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-ofxmlsoft · libxml2 · CWE-119 | Kritik9,8 | — | %4,9 | 11 Nis 2016 |
40Planlayın | CVE-2017-16931İstismar yok | parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference functioxmlsoft · libxml2 · CWE-119 | Kritik9,8 | — | %4,3 | 23 Kas 2017 |
40Planlayın | CVE-2017-7375İstismar yok | A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, Dxmlsoft · libxml2 · CWE-611 | Kritik9,8 | — | %2,6 | 19 Şub 2018 |
39İzleyin | CVE-2021-3517İstismar yok | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11.xmlsoft · libxml2 · CWE-787 | Yüksek8,6 | — | %17,0 | 19 May 2021 |
39İzleyin | CVE-2024-56171İstismar yok | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlscxmlsoft · libxml2 · CWE-416 | Kritik9,8 | — | %1,2 | 18 Şub 2025 |
37İzleyin | CVE-2004-0110Kavram kanıtı | Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execuxmlsoft · libxml | Yüksek7,5 | — | %24,2 | 15 Mar 2004 |
37İzleyin | CVE-2017-8872İstismar yok | The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or inforxmlsoft · libxml2 · CWE-125 | Kritik9,1 | — | %2,3 | 10 May 2017 |
36İzleyin | CVE-2017-15412İstismar yok | Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potegoogle · chrome · CWE-416 | Yüksek8,8 | — | %2,9 | 28 Ağu 2018 |
36İzleyin | CVE-2017-5130İstismar yok | An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remgoogle · chrome · CWE-787 | Yüksek8,8 | — | %2,7 | 7 Şub 2018 |
36İzleyin | CVE-2016-5131İstismar yok | Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denigoogle · chrome · CWE-416 | Yüksek8,8 | — | %2,3 | 23 Tem 2016 |
- CVE-2008-352947Planlayın
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to
KritikCVSS 10,0Kavram kanıtıEPSS %23xmlsoft · libxml212 Eyl 2008
- CVE-2004-098947Planlayın
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrar
KritikCVSS 10,0Kavram kanıtıEPSS %22xmlsoft · libxml1 Mar 2005
- CVE-2017-737646Planlayın
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling
KritikCVSS 9,8Kavram kanıtıEPSS %23xmlsoft · libxml219 Şub 2018
- CVE-2022-4030342Planlayın
An issue was discovered in libxml2 before 2.10.3.
YüksekCVSS 7,5İstismar yokEPSS %41xmlsoft · libxml222 Kas 2022
- CVE-2021-351842Planlayın
There's a flaw in libxml2 in versions before 2.9.11.
YüksekCVSS 8,8İstismar yokEPSS %22xmlsoft · libxml218 May 2021
- CVE-2016-465842Planlayın
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other produ
KritikCVSS 9,8İstismar yokEPSS %9apple · iphone os25 Eyl 2016
- CVE-2011-194441Planlayın
Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent
KritikCVSS 9,3Kavram kanıtıEPSS %13xmlsoft · libxml22 Eyl 2011
- CVE-2016-444841Planlayın
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vect
KritikCVSS 9,8İstismar yokEPSS %7hp · icewall federation agent9 Haz 2016
- CVE-2019-1106841Planlayın
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon r
KritikCVSS 9,8İstismar yokEPSS %5xmlsoft · libxslt10 Nis 2019
- CVE-2016-460941Planlayın
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,
KritikCVSS 9,8İstismar yokEPSS %5apple · iphone os21 Tem 2016
- CVE-2016-461041Planlayın
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,
KritikCVSS 9,8İstismar yokEPSS %5apple · iphone os21 Tem 2016
- CVE-2016-460741Planlayın
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,
KritikCVSS 9,8İstismar yokEPSS %5apple · iphone os21 Tem 2016
- CVE-2016-460841Planlayın
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,
KritikCVSS 9,8İstismar yokEPSS %5apple · iphone os21 Tem 2016
- CVE-2008-422641Planlayın
Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory
KritikCVSS 10,0İstismar yokEPSS %4xmlsoft · libxml25 Kas 2008
- CVE-2021-3056040Planlayın
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a
YüksekCVSS 8,8İstismar yokEPSS %18google · chrome3 Ağu 2021
- CVE-2015-871040Planlayın
The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of
KritikCVSS 9,8Kavram kanıtıEPSS %5xmlsoft · libxml211 Nis 2016
- CVE-2017-1693140Planlayın
parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference functio
KritikCVSS 9,8İstismar yokEPSS %4xmlsoft · libxml223 Kas 2017
- CVE-2017-737540Planlayın
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, D
KritikCVSS 9,8İstismar yokEPSS %3xmlsoft · libxml219 Şub 2018
- CVE-2021-351739İzleyin
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11.
YüksekCVSS 8,6İstismar yokEPSS %17xmlsoft · libxml219 May 2021
- CVE-2024-5617139İzleyin
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlsc
KritikCVSS 9,8İstismar yokEPSS %1xmlsoft · libxml218 Şub 2025
- CVE-2004-011037İzleyin
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execu
YüksekCVSS 7,5Kavram kanıtıEPSS %24xmlsoft · libxml15 Mar 2004
- CVE-2017-887237İzleyin
The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or infor
KritikCVSS 9,1İstismar yokEPSS %2xmlsoft · libxml210 May 2017
- CVE-2017-1541236İzleyin
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to pote
YüksekCVSS 8,8İstismar yokEPSS %3google · chrome28 Ağu 2018
- CVE-2017-513036İzleyin
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a rem
YüksekCVSS 8,8İstismar yokEPSS %3google · chrome7 Şub 2018
- CVE-2016-513136İzleyin
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a deni
YüksekCVSS 8,8İstismar yokEPSS %2google · chrome23 Tem 2016