Summary
Detail | |||
---|---|---|---|
Vendor | Xmlsoft | First view | 2003-12-31 |
Product | libxml2 | Last view | 2024-02-04 |
Version | Type | ||
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
Related : CVE
Date | Alert | Description | |
---|---|---|---|
7.5 | 2024-02-04 | CVE-2024-25062 | An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free. |
6.5 | 2023-10-06 | CVE-2023-45322 | libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail." |
6.5 | 2023-08-29 | CVE-2023-39615 | Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML file. NOTE: the vendor's position is that the product does not support the legacy SAX1 interface with custom callbacks; there is a crash even without crafted input. |
6.5 | 2023-04-24 | CVE-2023-29469 | An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the '\0' value). |
6.5 | 2023-04-24 | CVE-2023-28484 | In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c. |
7.8 | 2022-11-23 | CVE-2022-40304 | An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. |
7.5 | 2022-11-23 | CVE-2022-40303 | An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault. |
6.1 | 2022-07-28 | CVE-2016-3709 | Possible cross-site scripting vulnerability in libxml after commit 960f0e2. |
7.5 | 2022-07-05 | CVE-2022-2309 | NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered. |
6.5 | 2022-05-03 | CVE-2022-29824 | In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well. |
7.5 | 2022-02-26 | CVE-2022-23308 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
6.5 | 2021-07-09 | CVE-2021-3541 | A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service. |
8.6 | 2021-05-19 | CVE-2021-3517 | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application. |
8.8 | 2021-05-18 | CVE-2021-3518 | There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability. |
5.9 | 2021-05-14 | CVE-2021-3537 | A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability. |
6.5 | 2020-09-04 | CVE-2020-24977 | GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e. |
7.5 | 2020-01-21 | CVE-2020-7595 | xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. |
7.5 | 2020-01-21 | CVE-2019-20388 | xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. |
7.5 | 2019-12-24 | CVE-2019-19956 | xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. |
8.8 | 2018-08-28 | CVE-2017-15412 | Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
6.5 | 2018-08-16 | CVE-2018-14567 | libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251. |
6.5 | 2018-08-16 | CVE-2016-9598 | libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted XML document. NOTE: this vulnerability exists because of a missing fix for CVE-2016-4483. |
6.5 | 2018-08-16 | CVE-2016-9596 | libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack consumption) via a crafted XML document. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-3627. |
7.5 | 2018-07-30 | CVE-2016-9597 | It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705. |
7.5 | 2018-07-19 | CVE-2018-14404 | A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
34% (27) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
11% (9) | CWE-416 | Use After Free |
10% (8) | CWE-125 | Out-of-bounds Read |
6% (5) | CWE-476 | NULL Pointer Dereference |
6% (5) | CWE-399 | Resource Management Errors |
3% (3) | CWE-776 | Unrestricted Recursive Entity References in DTDs ('XML Bomb') |
3% (3) | CWE-415 | Double Free |
2% (2) | CWE-787 | Out-of-bounds Write |
2% (2) | CWE-674 | Uncontrolled Recursion |
2% (2) | CWE-611 | Information Leak Through XML External Entity File Disclosure |
2% (2) | CWE-401 | Failure to Release Memory Before Removing Last Reference ('Memory L... |
2% (2) | CWE-190 | Integer Overflow or Wraparound |
2% (2) | CWE-20 | Improper Input Validation |
1% (1) | CWE-770 | Allocation of Resources Without Limits or Throttling |
1% (1) | CWE-502 | Deserialization of Untrusted Data |
1% (1) | CWE-400 | Uncontrolled Resource Consumption ('Resource Exhaustion') |
1% (1) | CWE-264 | Permissions, Privileges, and Access Controls |
1% (1) | CWE-189 | Numeric Errors |
1% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
CAPEC : Common Attack Pattern Enumeration & Classification
id | Name |
---|---|
CAPEC-47 | Buffer Overflow via Parameter Expansion |
Oval Markup Language : Definitions
OvalID | Name |
---|---|
oval:org.mitre.oval:def:875 | XMLSoft Libxml2 Code Execution Vulnerability |
oval:org.mitre.oval:def:833 | XMLSoft Libxml2 Code Execution Vulnerability |
oval:org.mitre.oval:def:11626 | Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml ... |
oval:org.mitre.oval:def:1173 | Multiple Buffer Overflows in libXML2 |
oval:org.mitre.oval:def:10505 | Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly... |
oval:org.mitre.oval:def:9812 | libxml2 2.6.32 and earlier does not properly detect recursion during entity e... |
oval:org.mitre.oval:def:7968 | DSA-1631 libxml2 -- denial of service |
oval:org.mitre.oval:def:6496 | Libxml2 Recursive Entity Evaluation Bug Lets Remote Users Deny Service |
oval:org.mitre.oval:def:19740 | DSA-1631-1 libxml2 - denial of service |
oval:org.mitre.oval:def:17756 | USN-640-1 -- libxml2 vulnerability |
oval:org.mitre.oval:def:17731 | USN-644-1 -- libxml2 vulnerabilities |
oval:org.mitre.oval:def:21731 | ELSA-2008:0836: libxml2 security update (Moderate) |
oval:org.mitre.oval:def:29241 | RHSA-2008:0836 -- libxml2 security update (Moderate) |
oval:org.mitre.oval:def:8076 | DSA-1654 libxml2 -- buffer overflow |
oval:org.mitre.oval:def:6103 | Libxml2 Heap Overflow in xmlParseAttValueComplex() Lets Remote Users Execute ... |
oval:org.mitre.oval:def:18505 | DSA-1654-1 libxml2 - execution of arbitrary code |
oval:org.mitre.oval:def:13882 | USN-815-1 -- libxml2 vulnerabilities |
oval:org.mitre.oval:def:11760 | Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.... |
oval:org.mitre.oval:def:21739 | ELSA-2008:0884: libxml2 security update (Important) |
oval:org.mitre.oval:def:29030 | RHSA-2008:0884 -- libxml2 security update (Important) |
oval:org.mitre.oval:def:8639 | VMware libxml2 stack consumption vulnerability |
oval:org.mitre.oval:def:8132 | DSA-1859 libxml2 -- several vulnerabilities |
oval:org.mitre.oval:def:8116 | DSA-1861 libxml -- several vulnerabilities |
oval:org.mitre.oval:def:13712 | DSA-1861-1 libxml -- several |
oval:org.mitre.oval:def:13681 | DSA-1859-1 libxml2 -- several |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
73248 | libxml2 xpath.c Xpath Nodeset Processing Overflow |
73175 | jabberd14 Entity Expansion Recursion XML Nested Entity Handling DoS |
73174 | jabberd2 Entity Expansion Recursion XML Nested Entity Handling DoS |
73173 | citadel Entity Expansion Recursion XML Nested Entity Handling DoS |
73172 | Prosody Entity Expansion Recursion XML Nested Entity Handling DoS |
73171 | LuaExpat Entity Expansion Recursion XML Nested Entity Handling DoS |
73170 | ejabberd Entity Expansion Recursion XML Nested Entity Handling DoS |
69673 | Google Chrome XPath Handling Double-free Remote DoS |
69205 | libxml2 Crafted XML File XPath Axis Traversal DoS |
56990 | libxml2 DTD Element Declaration Handling Stack Consumption DoS |
56985 | libxml2 XML File Multiple Attribute Type Handling DoS |
48754 | libxml2 Predefined Entity Definition Crafted XML File Handling DoS |
48158 | libxml2 parser.c xmlParseAttValueComplex Function XML Entity Name Handling DoS |
48157 | libxml2 Entity Expansion Recursion XML Nested Entity Handling DoS |
47636 | libxml2 Crafted XML File Handling Recursion Limit DoS |
11324 | libxml2 Proxy FTP URL Processing Overflow |
11180 | libxml2 DNS Reply Overflows |
11179 | libxml2 FTP URL Processing Overflow |
4033 | libxml2 nanoftp URI Parsing Overflow |
4032 | libxml2 nanohttp URI Parsing Overflow |
ExploitDB Exploits
id | Description |
---|---|
8798 | Safari RSS feed:// Buffer Overflow via libxml2 Exploit PoC |
OpenVAS Exploits
id | Description |
---|---|
2012-12-14 | Name : SuSE Update for Chromium openSUSE-SU-2012:1637-1 (Chromium) File : nvt/gb_suse_2012_1637_1.nasl |
2012-12-13 | Name : SuSE Update for chromium openSUSE-SU-2012:1215-1 (chromium) File : nvt/gb_suse_2012_1215_1.nasl |
2012-12-06 | Name : Ubuntu Update for libxml2 USN-1656-1 File : nvt/gb_ubuntu_USN_1656_1.nasl |
2012-12-04 | Name : Debian Security Advisory DSA 2580-1 (libxml2) File : nvt/deb_2580_1.nasl |
2012-12-04 | Name : FreeBSD Ports: chromium File : nvt/freebsd_chromium24.nasl |
2012-12-04 | Name : CentOS Update for libxml2 CESA-2012:1512 centos5 File : nvt/gb_CESA-2012_1512_libxml2_centos5.nasl |
2012-12-04 | Name : CentOS Update for libxml2 CESA-2012:1512 centos6 File : nvt/gb_CESA-2012_1512_libxml2_centos6.nasl |
2012-12-04 | Name : RedHat Update for libxml2 RHSA-2012:1512-01 File : nvt/gb_RHSA-2012_1512-01_libxml2.nasl |
2012-12-04 | Name : Google Chrome Multiple Vulnerabilities-01 Dec2012 (Linux) File : nvt/gb_google_chrome_mult_vuln01_dec12_lin.nasl |
2012-12-04 | Name : Google Chrome Multiple Vulnerabilities-01 Dec2012 (Mac OS X) File : nvt/gb_google_chrome_mult_vuln01_dec12_macosx.nasl |
2012-12-04 | Name : Google Chrome Multiple Vulnerabilities-01 Dec2012 (Windows) File : nvt/gb_google_chrome_mult_vuln01_dec12_win.nasl |
2012-12-04 | Name : Mandriva Update for libxml2 MDVSA-2012:176 (libxml2) File : nvt/gb_mandriva_MDVSA_2012_176.nasl |
2012-10-13 | Name : Debian Security Advisory DSA 2555-1 (libxslt) File : nvt/deb_2555_1.nasl |
2012-10-12 | Name : Mandriva Update for libxslt MDVSA-2012:164 (libxslt) File : nvt/gb_mandriva_MDVSA_2012_164.nasl |
2012-10-05 | Name : Ubuntu Update for libxslt USN-1595-1 File : nvt/gb_ubuntu_USN_1595_1.nasl |
2012-10-03 | Name : Fedora Update for libxml2 FEDORA-2012-13824 File : nvt/gb_fedora_2012_13824_libxml2_fc16.nasl |
2012-10-03 | Name : Fedora Update for libxslt FEDORA-2012-14048 File : nvt/gb_fedora_2012_14048_libxslt_fc16.nasl |
2012-09-27 | Name : Fedora Update for libxml2 FEDORA-2012-13820 File : nvt/gb_fedora_2012_13820_libxml2_fc17.nasl |
2012-09-27 | Name : Fedora Update for libxslt FEDORA-2012-14083 File : nvt/gb_fedora_2012_14083_libxslt_fc17.nasl |
2012-09-17 | Name : CentOS Update for libxslt CESA-2012:1265 centos5 File : nvt/gb_CESA-2012_1265_libxslt_centos5.nasl |
2012-09-17 | Name : CentOS Update for libxslt CESA-2012:1265 centos6 File : nvt/gb_CESA-2012_1265_libxslt_centos6.nasl |
2012-09-17 | Name : RedHat Update for libxslt RHSA-2012:1265-01 File : nvt/gb_RHSA-2012_1265-01_libxslt.nasl |
2012-09-03 | Name : Google Chrome Multiple Vulnerabilities - Sep12 (Linux) File : nvt/gb_google_chrome_mult_vuln_sep12_lin.nasl |
2012-09-03 | Name : Google Chrome Multiple Vulnerabilities - Sep12 (Mac OS X) File : nvt/gb_google_chrome_mult_vuln_sep12_macosx.nasl |
2012-09-03 | Name : Google Chrome Multiple Vulnerabilities - Sep12 (Windows) File : nvt/gb_google_chrome_mult_vuln_sep12_win.nasl |
Information Assurance Vulnerability Management (IAVM)
id | Description |
---|---|
2015-B-0108 | Multiple Vulnerabilities in PHP Severity: Category I - VMSKEY: V0061365 |
2015-A-0199 | Multiple Vulnerabilities in Apple Mac OS X Severity: Category I - VMSKEY: V0061337 |
2015-B-0014 | Multiple Vulnerabilities in VMware ESXi 5.5 Severity: Category I - VMSKEY: V0058513 |
2015-B-0013 | Multiple Vulnerabilities in VMware ESXi 5.1 Severity: Category I - VMSKEY: V0058515 |
2014-B-0161 | Multiple Vulnerabilities in VMware ESXi 5.1 Severity: Category I - VMSKEY: V0057717 |
2013-A-0031 | Multiple Security Vulnerabilities in VMware ESX 4.1 and ESXi 4.1 Severity: Category I - VMSKEY: V0036787 |
2012-A-0153 | Multiple Vulnerabilities in VMware ESX 4.0 and ESXi 4.0 Severity: Category I - VMSKEY: V0033884 |
2012-A-0148 | Multiple Vulnerabilities in VMware ESXi 4.1 and ESX 4.1 Severity: Category I - VMSKEY: V0033794 |
2012-A-0073 | Multiple Vulnerabilities in VMware ESXi 4.1 and ESX 4.1 Severity: Category I - VMSKEY: V0032171 |
2009-T-0049 | Multiple Vulnerabilities in libxml2 Severity: Category I - VMSKEY: V0019911 |
2008-B-0078 | Multiple Vulnerabilities in VMware Severity: Category I - VMSKEY: V0017874 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | libxml2 file processing long entity overflow attempt RuleID : 15866 - Type : FILE-OTHER - Revision : 16 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2019-01-11 | Name: The remote device is missing a vendor-supplied security patch. File: juniper_jsa10916.nasl - Type: ACT_GATHER_INFO |
2019-01-08 | Name: The remote EulerOS host is missing a security update. File: EulerOS_SA-2019-1007.nasl - Type: ACT_GATHER_INFO |
2019-01-03 | Name: The remote Fedora host is missing a security update. File: fedora_2018-3b782350ff.nasl - Type: ACT_GATHER_INFO |
2019-01-03 | Name: The remote Fedora host is missing a security update. File: fedora_2018-aafdbb5554.nasl - Type: ACT_GATHER_INFO |
2018-12-28 | Name: The remote EulerOS host is missing a security update. File: EulerOS_SA-2018-1446.nasl - Type: ACT_GATHER_INFO |
2018-10-26 | Name: The remote EulerOS Virtualization host is missing a security update. File: EulerOS_SA-2018-1336.nasl - Type: ACT_GATHER_INFO |
2018-09-28 | Name: The remote Debian host is missing a security update. File: debian_DLA-1524.nasl - Type: ACT_GATHER_INFO |
2018-09-18 | Name: The remote EulerOS Virtualization host is missing a security update. File: EulerOS_SA-2018-1255.nasl - Type: ACT_GATHER_INFO |
2018-09-18 | Name: The remote EulerOS Virtualization host is missing multiple security updates. File: EulerOS_SA-2018-1257.nasl - Type: ACT_GATHER_INFO |
2018-09-18 | Name: The remote EulerOS Virtualization host is missing multiple security updates. File: EulerOS_SA-2018-1258.nasl - Type: ACT_GATHER_INFO |
2018-09-07 | Name: The remote Amazon Linux AMI host is missing a security update. File: ala_ALAS-2018-1072.nasl - Type: ACT_GATHER_INFO |
2018-08-17 | Name: The remote PhotonOS host is missing multiple security updates. File: PhotonOS_PHSA-2017-0001.nasl - Type: ACT_GATHER_INFO |
2018-08-17 | Name: The remote PhotonOS host is missing multiple security updates. File: PhotonOS_PHSA-2017-0024.nasl - Type: ACT_GATHER_INFO |
2018-08-17 | Name: The remote PhotonOS host is missing multiple security updates. File: PhotonOS_PHSA-2017-0029.nasl - Type: ACT_GATHER_INFO |
2018-08-17 | Name: The remote PhotonOS host is missing multiple security updates. File: PhotonOS_PHSA-2017-0039.nasl - Type: ACT_GATHER_INFO |
2018-08-10 | Name: The remote Fedora host is missing a security update. File: fedora_2018-e198cf4a64.nasl - Type: ACT_GATHER_INFO |
2018-08-03 | Name: The antivirus service running on the remote host is affected by multiple vuln... File: clamav_0_100_1.nasl - Type: ACT_GATHER_INFO |
2018-07-10 | Name: The remote FreeBSD host is missing a security-related update. File: freebsd_pkg_d1e9d8c5839b11e896109c5c8e75236a.nasl - Type: ACT_GATHER_INFO |
2018-06-28 | Name: The remote EulerOS host is missing multiple security updates. File: EulerOS_SA-2018-1156.nasl - Type: ACT_GATHER_INFO |
2018-05-02 | Name: The remote EulerOS host is missing multiple security updates. File: EulerOS_SA-2018-1088.nasl - Type: ACT_GATHER_INFO |
2018-05-02 | Name: The remote EulerOS host is missing multiple security updates. File: EulerOS_SA-2018-1089.nasl - Type: ACT_GATHER_INFO |
2018-03-28 | Name: The remote Fedora host is missing a security update. File: fedora_2018-faff5f661e.nasl - Type: ACT_GATHER_INFO |
2018-03-20 | Name: The remote EulerOS host is missing multiple security updates. File: EulerOS_SA-2018-1070.nasl - Type: ACT_GATHER_INFO |
2018-03-20 | Name: The remote EulerOS host is missing multiple security updates. File: EulerOS_SA-2018-1071.nasl - Type: ACT_GATHER_INFO |
2018-02-15 | Name: The remote Fedora host is missing a security update. File: fedora_2018-a6b59d8f78.nasl - Type: ACT_GATHER_INFO |