İçeriğe atla
Noroxi

xmlsoft kayıtları

xmlsoft üreticisine ait 144 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
10
Düzeltme kaydı olan
%97,2
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

144 kayıt
  • CVE-2008-3529
    47Planlayın

    Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to

    KritikCVSS 10,0Kavram kanıtıEPSS %23

    xmlsoft · libxml212 Eyl 2008

  • CVE-2004-0989
    47Planlayın

    Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrar

    KritikCVSS 10,0Kavram kanıtıEPSS %22

    xmlsoft · libxml1 Mar 2005

  • CVE-2017-7376
    46Planlayın

    Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling

    KritikCVSS 9,8Kavram kanıtıEPSS %23

    xmlsoft · libxml219 Şub 2018

  • CVE-2022-40303
    42Planlayın

    An issue was discovered in libxml2 before 2.10.3.

    YüksekCVSS 7,5İstismar yokEPSS %41

    xmlsoft · libxml222 Kas 2022

  • CVE-2021-3518
    42Planlayın

    There's a flaw in libxml2 in versions before 2.9.11.

    YüksekCVSS 8,8İstismar yokEPSS %22

    xmlsoft · libxml218 May 2021

  • CVE-2016-4658
    42Planlayın

    xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other produ

    KritikCVSS 9,8İstismar yokEPSS %9

    apple · iphone os25 Eyl 2016

  • CVE-2011-1944
    41Planlayın

    Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent

    KritikCVSS 9,3Kavram kanıtıEPSS %13

    xmlsoft · libxml22 Eyl 2011

  • CVE-2016-4448
    41Planlayın

    Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vect

    KritikCVSS 9,8İstismar yokEPSS %7

    hp · icewall federation agent9 Haz 2016

  • CVE-2019-11068
    41Planlayın

    libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon r

    KritikCVSS 9,8İstismar yokEPSS %5

    xmlsoft · libxslt10 Nis 2019

  • CVE-2016-4609
    41Planlayın

    libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,

    KritikCVSS 9,8İstismar yokEPSS %5

    apple · iphone os21 Tem 2016

  • CVE-2016-4610
    41Planlayın

    libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,

    KritikCVSS 9,8İstismar yokEPSS %5

    apple · iphone os21 Tem 2016

  • CVE-2016-4607
    41Planlayın

    libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,

    KritikCVSS 9,8İstismar yokEPSS %5

    apple · iphone os21 Tem 2016

  • CVE-2016-4608
    41Planlayın

    libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2,

    KritikCVSS 9,8İstismar yokEPSS %5

    apple · iphone os21 Tem 2016

  • CVE-2008-4226
    41Planlayın

    Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory

    KritikCVSS 10,0İstismar yokEPSS %4

    xmlsoft · libxml25 Kas 2008

  • CVE-2021-30560
    40Planlayın

    Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a

    YüksekCVSS 8,8İstismar yokEPSS %18

    google · chrome3 Ağu 2021

  • CVE-2015-8710
    40Planlayın

    The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    xmlsoft · libxml211 Nis 2016

  • CVE-2017-16931
    40Planlayın

    parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference functio

    KritikCVSS 9,8İstismar yokEPSS %4

    xmlsoft · libxml223 Kas 2017

  • CVE-2017-7375
    40Planlayın

    A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, D

    KritikCVSS 9,8İstismar yokEPSS %3

    xmlsoft · libxml219 Şub 2018

  • CVE-2021-3517
    39İzleyin

    There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11.

    YüksekCVSS 8,6İstismar yokEPSS %17

    xmlsoft · libxml219 May 2021

  • CVE-2024-56171
    39İzleyin

    libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlsc

    KritikCVSS 9,8İstismar yokEPSS %1

    xmlsoft · libxml218 Şub 2025

  • CVE-2004-0110
    37İzleyin

    Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execu

    YüksekCVSS 7,5Kavram kanıtıEPSS %24

    xmlsoft · libxml15 Mar 2004

  • CVE-2017-8872
    37İzleyin

    The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or infor

    KritikCVSS 9,1İstismar yokEPSS %2

    xmlsoft · libxml210 May 2017

  • CVE-2017-15412
    36İzleyin

    Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to pote

    YüksekCVSS 8,8İstismar yokEPSS %3

    google · chrome28 Ağu 2018

  • CVE-2017-5130
    36İzleyin

    An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a rem

    YüksekCVSS 8,8İstismar yokEPSS %3

    google · chrome7 Şub 2018

  • CVE-2016-5131
    36İzleyin

    Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a deni

    YüksekCVSS 8,8İstismar yokEPSS %2

    google · chrome23 Tem 2016