This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
Summuary | |
---|---|
CPE Name | cpe:/a:xmlsoft:libxml2:2.6.6 |
Detail | |||
---|---|---|---|
Vendor | Xmlsoft | First view | 2005-03-01 |
Product | libxml2 | Last view | 2018-02-19 |
Version | 2.6.6 | Type | Application |
Edition | |||
Language | |||
Update | |||
CPE Product | cpe:/a:xmlsoft:libxml2 |
Activity : Overall
Related : CVE
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
Date | Alert | Access Vector | Access Complexity | Authentication | ||
---|---|---|---|---|---|---|
7.5 | 2018-02-19 | CVE-2017-7375 | Network | Low | None Requ... | |
6.8 | 2018-02-07 | CVE-2017-5130 | Network | Medium | None Requ... | |
5 | 2017-11-23 | CVE-2017-16932 | Network | Low | None Requ... | |
7.5 | 2017-11-23 | CVE-2017-16931 | Network | Low | None Requ... | |
6.8 | 2016-11-15 | CVE-2016-9318 | Network | Medium | None Requ... | |
Date | Alert | Access Vector | Access Complexity | Authentication | ||
---|---|---|---|---|---|---|
6.8 | 2016-07-23 | CVE-2016-5131 | Network | Medium | None Requ... | |
5.8 | 2016-06-09 | CVE-2016-4449 | Network | Medium | None Requ... | |
10 | 2016-06-09 | CVE-2016-4448 | Network | Low | None Requ... | |
5 | 2016-06-09 | CVE-2016-4447 | Network | Low | None Requ... | |
5 | 2016-05-17 | CVE-2016-3627 | Network | Low | None Requ... | |
5 | 2016-05-16 | CVE-2015-6838 | Network | Low | None Requ... | |
5 | 2016-05-16 | CVE-2015-6837 | Network | Low | None Requ... | |
5 | 2015-12-15 | CVE-2015-8317 | Network | Low | None Requ... | |
5.8 | 2015-12-15 | CVE-2015-8242 | Network | Medium | None Requ... | |
6.4 | 2015-12-15 | CVE-2015-8241 | Network | Low | None Requ... | |
5 | 2015-12-15 | CVE-2015-7500 | Network | Low | None Requ... | |
5 | 2015-12-15 | CVE-2015-7499 | Network | Low | None Requ... | |
5 | 2015-12-15 | CVE-2015-7498 | Network | Low | None Requ... | |
5 | 2015-12-15 | CVE-2015-7497 | Network | Low | None Requ... | |
7.1 | 2015-12-15 | CVE-2015-5312 | Network | Medium | None Requ... | |
5 | 2014-11-04 | CVE-2014-3660 | Network | Low | None Requ... | |
6.8 | 2014-01-21 | CVE-2013-0339 | Network | Medium | None Requ... | |
5 | 2013-07-10 | CVE-2013-2877 | Network | Low | None Requ... | |
4.3 | 2013-04-25 | CVE-2013-0338 | Network | Medium | None Requ... |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
53% (14) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
11% (3) | CWE-399 | Resource Management Errors |
7% (2) | CWE-611 | Information Leak Through XML External Entity File Disclosure |
7% (2) | CWE-20 | Improper Input Validation |
3% (1) | CWE-787 | Out-of-bounds Write |
% | id | Name |
---|---|---|
3% (1) | CWE-416 | Use After Free |
3% (1) | CWE-400 | Uncontrolled Resource Consumption ('Resource Exhaustion') |
3% (1) | CWE-264 | Permissions, Privileges, and Access Controls |
3% (1) | CWE-189 | Numeric Errors |
CAPEC : Common Attack Pattern Enumeration & Classification
id | Name |
---|---|
CAPEC-47 | Buffer Overflow via Parameter Expansion |
Oval Markup Language : Definitions
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
OvalID | Name |
---|---|
oval:org.mitre.oval:def:13253 | USN-1016-1 -- libxml2 vulnerability |
oval:org.mitre.oval:def:12709 | DSA-2128-1 libxml2 -- invalid memory access |
oval:org.mitre.oval:def:12148 | Vulnerability in libxml2 in Google Chrome before 7.0.517.44 |
oval:org.mitre.oval:def:20663 | VMware vSphere security updates for the authentication service and third part... |
oval:org.mitre.oval:def:26564 | Allows remote attackers to cause a denial of service or possibly have unknown... |
id | Name |
---|---|
oval:org.mitre.oval:def:26857 | DEPRECATED: ELSA-2012-1265 -- libxslt security update (important) |
oval:org.mitre.oval:def:20018 | DSA-2652-1 libxml2 - external entity expansion |
oval:org.mitre.oval:def:25923 | SUSE-SU-2013:0744-1 -- Security update for libxml2 |
oval:org.mitre.oval:def:25816 | SUSE-SU-2013:0743-1 -- Security update for libxml2 |
oval:org.mitre.oval:def:25714 | SUSE-SU-2013:1625-1 -- Security update for libxml2 |
oval:org.mitre.oval:def:1173 | Multiple Buffer Overflows in libXML2 |
oval:org.mitre.oval:def:10505 | Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly... |
oval:org.mitre.oval:def:20894 | RHSA-2013:0581: libxml2 security update (Moderate) |
oval:org.mitre.oval:def:20491 | VMware vSphere, ESX and ESXi updates to third party libraries |
oval:org.mitre.oval:def:18166 | USN-1782-1 -- libxml2 vulnerability |
oval:org.mitre.oval:def:23965 | DEPRECATED: ELSA-2013:0581: libxml2 security update (Moderate) |
oval:org.mitre.oval:def:23449 | ELSA-2013:0581: libxml2 security update (Moderate) |
oval:org.mitre.oval:def:27000 | DEPRECATED: ELSA-2013-0581 -- libxml2 security update (moderate) |
oval:org.mitre.oval:def:21665 | RHSA-2012:1512: libxml2 security update (Important) |
oval:org.mitre.oval:def:20771 | RHSA-2013:0217: mingw32-libxml2 security update (Important) |
oval:org.mitre.oval:def:20411 | VMware ESXi and ESX security update for third party library |
oval:org.mitre.oval:def:19412 | DSA-2580-1 libxml2 - buffer overflow |
oval:org.mitre.oval:def:17901 | USN-1656-1 -- libxml2 vulnerability |
oval:org.mitre.oval:def:23922 | ELSA-2012:1512: libxml2 security update (Important) |
oval:org.mitre.oval:def:23888 | ELSA-2013:0217: mingw32-libxml2 security update (Important) |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
73248 | libxml2 xpath.c Xpath Nodeset Processing Overflow |
69205 | libxml2 Crafted XML File XPath Axis Traversal DoS |
48158 | libxml2 parser.c xmlParseAttValueComplex Function XML Entity Name Handling DoS |
47636 | libxml2 Crafted XML File Handling Recursion Limit DoS |
11324 | libxml2 Proxy FTP URL Processing Overflow |
id | Description |
---|---|
11180 | libxml2 DNS Reply Overflows |
11179 | libxml2 FTP URL Processing Overflow |
ExploitDB Exploits
id | Description |
---|---|
8798 | Safari RSS feed:// Buffer Overflow via libxml2 Exploit PoC |
OpenVAS Exploits
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id | Description |
---|---|
2012-12-14 | Name : SuSE Update for Chromium openSUSE-SU-2012:1637-1 (Chromium) File : nvt/gb_suse_2012_1637_1.nasl |
2012-12-13 | Name : SuSE Update for chromium openSUSE-SU-2012:1215-1 (chromium) File : nvt/gb_suse_2012_1215_1.nasl |
2012-12-06 | Name : Ubuntu Update for libxml2 USN-1656-1 File : nvt/gb_ubuntu_USN_1656_1.nasl |
2012-12-04 | Name : RedHat Update for libxml2 RHSA-2012:1512-01 File : nvt/gb_RHSA-2012_1512-01_libxml2.nasl |
2012-12-04 | Name : Mandriva Update for libxml2 MDVSA-2012:176 (libxml2) File : nvt/gb_mandriva_MDVSA_2012_176.nasl |
id | Description |
---|---|
2012-12-04 | Name : Debian Security Advisory DSA 2580-1 (libxml2) File : nvt/deb_2580_1.nasl |
2012-12-04 | Name : FreeBSD Ports: chromium File : nvt/freebsd_chromium24.nasl |
2012-12-04 | Name : CentOS Update for libxml2 CESA-2012:1512 centos5 File : nvt/gb_CESA-2012_1512_libxml2_centos5.nasl |
2012-12-04 | Name : CentOS Update for libxml2 CESA-2012:1512 centos6 File : nvt/gb_CESA-2012_1512_libxml2_centos6.nasl |
2012-12-04 | Name : Google Chrome Multiple Vulnerabilities-01 Dec2012 (Linux) File : nvt/gb_google_chrome_mult_vuln01_dec12_lin.nasl |
2012-12-04 | Name : Google Chrome Multiple Vulnerabilities-01 Dec2012 (Mac OS X) File : nvt/gb_google_chrome_mult_vuln01_dec12_macosx.nasl |
2012-12-04 | Name : Google Chrome Multiple Vulnerabilities-01 Dec2012 (Windows) File : nvt/gb_google_chrome_mult_vuln01_dec12_win.nasl |
2012-10-13 | Name : Debian Security Advisory DSA 2555-1 (libxslt) File : nvt/deb_2555_1.nasl |
2012-10-12 | Name : Mandriva Update for libxslt MDVSA-2012:164 (libxslt) File : nvt/gb_mandriva_MDVSA_2012_164.nasl |
2012-10-05 | Name : Ubuntu Update for libxslt USN-1595-1 File : nvt/gb_ubuntu_USN_1595_1.nasl |
2012-10-03 | Name : Fedora Update for libxml2 FEDORA-2012-13824 File : nvt/gb_fedora_2012_13824_libxml2_fc16.nasl |
2012-10-03 | Name : Fedora Update for libxslt FEDORA-2012-14048 File : nvt/gb_fedora_2012_14048_libxslt_fc16.nasl |
2012-09-27 | Name : Fedora Update for libxml2 FEDORA-2012-13820 File : nvt/gb_fedora_2012_13820_libxml2_fc17.nasl |
2012-09-27 | Name : Fedora Update for libxslt FEDORA-2012-14083 File : nvt/gb_fedora_2012_14083_libxslt_fc17.nasl |
2012-09-17 | Name : RedHat Update for libxslt RHSA-2012:1265-01 File : nvt/gb_RHSA-2012_1265-01_libxslt.nasl |
2012-09-17 | Name : CentOS Update for libxslt CESA-2012:1265 centos5 File : nvt/gb_CESA-2012_1265_libxslt_centos5.nasl |
2012-09-17 | Name : CentOS Update for libxslt CESA-2012:1265 centos6 File : nvt/gb_CESA-2012_1265_libxslt_centos6.nasl |
2012-09-03 | Name : Google Chrome Multiple Vulnerabilities - Sep12 (Windows) File : nvt/gb_google_chrome_mult_vuln_sep12_win.nasl |
2012-09-03 | Name : Google Chrome Multiple Vulnerabilities - Sep12 (Linux) File : nvt/gb_google_chrome_mult_vuln_sep12_lin.nasl |
2012-09-03 | Name : Google Chrome Multiple Vulnerabilities - Sep12 (Mac OS X) File : nvt/gb_google_chrome_mult_vuln_sep12_macosx.nasl |
Information Assurance Vulnerability Management (IAVM)
id | Description |
---|---|
2015-B-0108 | Multiple Vulnerabilities in PHP Severity : Category I - VMSKEY : V0061365 |
2015-A-0199 | Multiple Vulnerabilities in Apple Mac OS X Severity : Category I - VMSKEY : V0061337 |
2015-B-0014 | Multiple Vulnerabilities in VMware ESXi 5.5 Severity : Category I - VMSKEY : V0058513 |
2015-B-0013 | Multiple Vulnerabilities in VMware ESXi 5.1 Severity : Category I - VMSKEY : V0058515 |
2014-B-0161 | Multiple Vulnerabilities in VMware ESXi 5.1 Severity : Category I - VMSKEY : V0057717 |
id | Description |
---|---|
2013-A-0031 | Multiple Security Vulnerabilities in VMware ESX 4.1 and ESXi 4.1 Severity : Category I - VMSKEY : V0036787 |
2012-A-0153 | Multiple Vulnerabilities in VMware ESX 4.0 and ESXi 4.0 Severity : Category I - VMSKEY : V0033884 |
2012-A-0148 | Multiple Vulnerabilities in VMware ESXi 4.1 and ESX 4.1 Severity : Category I - VMSKEY : V0033794 |
2012-A-0073 | Multiple Vulnerabilities in VMware ESXi 4.1 and ESX 4.1 Severity : Category I - VMSKEY : V0032171 |
2008-B-0078 | Multiple Vulnerabilities in VMware Severity : Category I - VMSKEY : V0017874 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | libxml2 file processing long entity overflow attempt RuleID : 15866 - Type : FILE-OTHER - Revision : 16 |
Nessus® Vulnerability Scanner
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id | Description |
---|---|
2018-03-20 | Name : The remote EulerOS host is missing multiple security updates. File : EulerOS_SA-2018-1070.nasl - Type : ACT_GATHER_INFO |
2018-03-20 | Name : The remote EulerOS host is missing multiple security updates. File : EulerOS_SA-2018-1071.nasl - Type : ACT_GATHER_INFO |
2018-02-15 | Name : The remote Fedora host is missing a security update. File : fedora_2018-a6b59d8f78.nasl - Type : ACT_GATHER_INFO |
2018-01-31 | Name : The remote Fedora host is missing a security update. File : fedora_2018-db610fff5b.nasl - Type : ACT_GATHER_INFO |
2018-01-15 | Name : The remote Fedora host is missing a security update. File : fedora_2017-f2f3fa09e3.nasl - Type : ACT_GATHER_INFO |
id | Description |
---|---|
2018-01-02 | Name : The remote Fedora host is missing a security update. File : fedora_2017-ea44f172e3.nasl - Type : ACT_GATHER_INFO |
2017-12-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-3504-1.nasl - Type : ACT_GATHER_INFO |
2017-12-01 | Name : The remote Debian host is missing a security update. File : debian_DLA-1194.nasl - Type : ACT_GATHER_INFO |
2017-11-27 | Name : The remote Debian host is missing a security update. File : debian_DLA-1188.nasl - Type : ACT_GATHER_INFO |
2017-11-10 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201711-01.nasl - Type : ACT_GATHER_INFO |
2017-10-30 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2017-1221.nasl - Type : ACT_GATHER_INFO |
2017-10-23 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_a692bffeb6ad11e7a1c2e8e0b747a45a.nasl - Type : ACT_GATHER_INFO |
2017-10-23 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201710-24.nasl - Type : ACT_GATHER_INFO |
2017-10-23 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2017-2997.nasl - Type : ACT_GATHER_INFO |
2017-10-18 | Name : A web browser installed on the remote Windows host is affected by multiple vu... File : google_chrome_62_0_3202_62.nasl - Type : ACT_GATHER_INFO |
2017-10-18 | Name : A web browser installed on the remote macOS or Mac OS X host is affected by m... File : macosx_google_chrome_62_0_3202_62.nasl - Type : ACT_GATHER_INFO |
2017-09-19 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-3424-1.nasl - Type : ACT_GATHER_INFO |
2017-08-23 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3952.nasl - Type : ACT_GATHER_INFO |
2017-07-10 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2017-1813-1.nasl - Type : ACT_GATHER_INFO |
2017-07-07 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2017-793.nasl - Type : ACT_GATHER_INFO |
2017-07-03 | Name : The remote Debian host is missing a security update. File : debian_DLA-1008.nasl - Type : ACT_GATHER_INFO |
2017-07-03 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2017-1743-1.nasl - Type : ACT_GATHER_INFO |
2017-06-14 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2017-1557-1.nasl - Type : ACT_GATHER_INFO |
2017-05-23 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2017-1366-1.nasl - Type : ACT_GATHER_INFO |
2017-05-03 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2017-1070.nasl - Type : ACT_GATHER_INFO |