cbcvebase.

Debian Libxml2 vulnerabilities

111 known vulnerabilities affecting debian/libxml2.

Total CVEs
111
CISA KEV
0
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL14HIGH38MEDIUM44LOW15

Vulnerabilities

Page 1 of 6
CVE-2022-40303P2HIGHCVSS 7.5Exploitedfixed in libxml2 2.9.14+dfsg-1.1 (bookworm)2022
CVE-2022-40303 [HIGH] CVE-2022-40303: libxml2 - An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte ... An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault. Scope: local bookworm: resolved (fixed in 2.9.14+dfsg-1.1) bullseye: resol
debian
CVE-2022-40304P2HIGHCVSS 7.8Exploitedfixed in libxml2 2.9.14+dfsg-1.1 (bookworm)2022
CVE-2022-40304 [HIGH] CVE-2022-40304: libxml2 - An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity def... An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. Scope: local bookworm: resolved (fixed in 2.9.14+dfsg-1.1) bullseye: resolved (fixed in 2.9.10+dfsg-6.7+deb11u3) forky: resolved (fixed in 2.9.14+dfsg-1.1) s
debian
CVE-2008-3529P2CRITICALCVSS 10.0PoCfixed in libxml2 2.6.32.dfsg-4 (bookworm)2008
CVE-2008-3529 [CRITICAL] CVE-2008-3529: libxml2 - Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c i... Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name. Scope: local bookworm: resolved (fixed in 2.6.32.dfsg-4) bullseye: resolved (fixed in 2.6.32.dfsg-4) forky: resolved (fixed in 2.6.32.dfs
debian
CVE-2011-1944P3CRITICALCVSS 9.3PoCfixed in libxml2 2.7.8.dfsg-3 (bookworm)2011
CVE-2011-1944 [CRITICAL] CVE-2011-1944: libxml2 - Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.... Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.
debian
CVE-2004-0989P3CRITICALCVSS 10.0PoCfixed in libxml2 2.6.11-5 (bookworm)2004
CVE-2004-0989 [CRITICAL] CVE-2004-0989: libxml2 - Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly ot... Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows relat
debian
CVE-2017-7376P2CRITICALCVSS 9.8fixed in libxml2 2.9.4+dfsg1-3.1 (bookworm)2017
CVE-2017-7376 [CRITICAL] CVE-2017-7376: libxml2 - Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by ... Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects. Scope: local bookworm: resolved (fixed in 2.9.4+dfsg1-3.1) bullseye: resolved (fixed in 2.9.4+dfsg1-3.1) forky: resolved (fixed in 2.9.4+dfsg1-3.1) sid: resolved (fixed in 2.9.4+dfsg1-3.1) trixie: resolved (fixed in
debian
CVE-2004-0110P3HIGHCVSS 7.5PoCfixed in libxml2 2.6.6-1 (bookworm)2004
CVE-2004-0110 [HIGH] CVE-2004-0110: libxml2 - Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (... Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL. Scope: local bookworm: resolved (fixed in 2.6.6-1) bullseye: resolved (fixed in 2.6.6-1) forky: resolved (fixed in 2.6.6-1) sid: resolved (fixed in 2.6.6-1) trixie: resolved (fixed in 2.6.6-1)
debian
CVE-2021-3517P3HIGHCVSS 8.6fixed in libxml2 2.9.10+dfsg-6.6 (bookworm)2021
CVE-2021-3517 [HIGH] CVE-2021-3517: libxml2 - There is a flaw in the xml entity encoding functionality of libxml2 in versions ... There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confide
debian
CVE-2014-0191P4MEDIUMCVSS 4.3PoCfixed in libxml2 2.9.1+dfsg1-4 (bookworm)2014
CVE-2014-0191 [MEDIUM] CVE-2014-0191: libxml2 - The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as ... The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (
debian
CVE-2016-1839P4MEDIUMCVSS 5.5PoCfixed in libxml2 2.9.3+dfsg1-1.1 (bookworm)2016
CVE-2016-1839 [MEDIUM] CVE-2016-1839: libxml2 - The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS befo... The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. Scope: local bookworm: resolved (fixed in 2.9.3+dfsg1-1.1) bullseye: resolved (fixed in 2.9.3+dfsg1-1
debian
CVE-2016-1838P4MEDIUMCVSS 5.5PoCfixed in libxml2 2.9.3+dfsg1-1.1 (bookworm)2016
CVE-2016-1838 [MEDIUM] CVE-2016-1838: libxml2 - The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used ... The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. Scope: local bookworm: resolved (fixed in 2.9.3+dfsg1-1.1) bullseye: resolved (fixed
debian
CVE-2016-4658P3CRITICALCVSS 9.8fixed in libxml2 2.9.4+dfsg1-2.1 (bookworm)2016
CVE-2016-4658 [CRITICAL] CVE-2016-4658: libxml2 - xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before ... xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document. Scope: local book
debian
CVE-2021-3518P3HIGHCVSS 8.8fixed in libxml2 2.9.10+dfsg-6.6 (bookworm)2021
CVE-2021-3518 [HIGH] CVE-2021-3518: libxml2 - There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to ... There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability. Scope: local bookworm: resolved (fixed in 2.9.10+dfsg-6.6) bullseye: resolved (fixed in 2.9.10+
debian
CVE-2025-49796P3CRITICALCVSS 9.1fixed in libxml2 2.9.14+dfsg-1.3~deb12u3 (bookworm)2025
CVE-2025-49796 [CRITICAL] CVE-2025-49796: libxml2 - A vulnerability was found in libxml2. Processing certain sch:name elements from ... A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory. Scope: loca
debian
CVE-2017-7375P3CRITICALCVSS 9.8fixed in libxml2 2.9.4+dfsg1-3.1 (bookworm)2017
CVE-2017-7375 [CRITICAL] CVE-2017-7375: libxml2 - A flaw in libxml2 allows remote XML entity inclusion with default parser flags (... A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from
debian
CVE-2025-49794P3CRITICALCVSS 9.1fixed in libxml2 2.9.14+dfsg-1.3~deb12u3 (bookworm)2025
CVE-2025-49794 [CRITICAL] CVE-2025-49794: libxml2 - A use-after-free vulnerability was found in libxml2. This issue occurs when pars... A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors. Scope: l
debian
CVE-2024-56171P3HIGHCVSS 7.8fixed in libxml2 2.9.14+dfsg-1.3~deb12u2 (bookworm)2024
CVE-2024-56171 [HIGH] CVE-2024-56171: libxml2 - libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchem... libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used. Scope: local bookworm: resolved (fixed in 2.9.14+dfsg-1.3~deb12u2)
debian
CVE-2016-4448P3CRITICALCVSS 9.8fixed in libxml2 2.9.4+dfsg1-1 (bookworm)2016
CVE-2016-4448 [CRITICAL] CVE-2016-4448: libxml2 - Format string vulnerability in libxml2 before 2.9.4 allows attackers to have uns... Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. Scope: local bookworm: resolved (fixed in 2.9.4+dfsg1-1) bullseye: resolved (fixed in 2.9.4+dfsg1-1) forky: resolved (fixed in 2.9.4+dfsg1-1) sid: resolved (fixed in 2.9.4+dfsg1-1) trixie: resolved (fixed in 2.9.4+dfsg1-1
debian
CVE-2017-15412P3HIGHCVSS 8.8fixed in libxml2 2.9.4+dfsg1-5.2 (bookworm)2017
CVE-2017-15412 [HIGH] CVE-2017-15412: libxml2 - Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3... Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 2.9.4+dfsg1-5.2) bullseye: resolved (fixed in 2.9.4+dfsg1-5.2) forky: resolved (fixed in 2.9.4+dfsg1-5.2) sid: resolved (fixed in
debian
CVE-2017-5130P3HIGHCVSS 8.8fixed in libxml2 2.9.4+dfsg1-5.1 (bookworm)2017
CVE-2017-5130 [HIGH] CVE-2017-5130: libxml2 - An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Ch... An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file. Scope: local bookworm: resolved (fixed in 2.9.4+dfsg1-5.1) bullseye: resolved (fixed in 2.9.4+dfsg1-5.1) forky: resolved (fixed in 2.9.4+dfsg1-5.1) sid: r
debian
Debian Libxml2 vulnerabilities | cvebase