Debian Libxml2 vulnerabilities
111 known vulnerabilities affecting debian/libxml2.
Total CVEs
111
CISA KEV
0
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL14HIGH38MEDIUM44LOW15
Vulnerabilities
Page 4 of 6
CVE-2022-29824P4MEDIUMCVSS 6.5fixed in libxml2 2.9.14+dfsg-1 (bookworm)2022
CVE-2022-29824 [MEDIUM] CVE-2022-29824: libxml2 - In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) a...
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
debian
CVE-2020-24977P4LOWCVSS 6.5fixed in libxml2 2.9.10+dfsg-6.2 (bookworm)2020
CVE-2020-24977 [MEDIUM] CVE-2020-24977: libxml2 - GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xml...
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
Scope: local
bookworm: resolved (fixed in 2.9.10+dfsg-6.2)
bullseye: resolved (fixed in 2.9.10+dfsg-6.2)
forky: resolved (fixed in 2.9.10+dfsg-6.2)
sid: resolved (fixed in 2.9.10+dfsg-6.2)
trixie
debian
CVE-2015-5312P4MEDIUMCVSS 5.0fixed in libxml2 2.9.3+dfsg1-1 (bookworm)2015
CVE-2015-5312 [MEDIUM] CVE-2015-5312: libxml2 - The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does...
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
Scope: local
bookworm: resolved (fixed in 2.9.3+dfsg1-1)
bullseye: resolved (fixed in 2.9.3+
debian
CVE-2015-7498P4MEDIUMCVSS 5.0fixed in libxml2 2.9.3+dfsg1-1 (bookworm)2015
CVE-2015-7498 [MEDIUM] CVE-2015-7498: libxml2 - Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml...
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
Scope: local
bookworm: resolved (fixed in 2.9.3+dfsg1-1)
bullseye: resolved (fixed in 2.9.3+dfsg1-1)
forky: resolved (
debian
CVE-2016-4449P4HIGHCVSS 7.1fixed in libxml2 2.9.3+dfsg1-1.1 (bookworm)2016
CVE-2016-4449 [HIGH] CVE-2016-4449: libxml2 - XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities functi...
XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.9.3+dfsg1-1.1)
bullseye: resolved (fixed
debian
CVE-2021-3541P4MEDIUMCVSS 6.5fixed in libxml2 2.9.10+dfsg-6.7 (bookworm)2021
CVE-2021-3541 [MEDIUM] CVE-2021-3541: libxml2 - A flaw was found in libxml2. Exponential entity expansion attack its possible by...
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
Scope: local
bookworm: resolved (fixed in 2.9.10+dfsg-6.7)
bullseye: resolved (fixed in 2.9.10+dfsg-6.7)
forky: resolved (fixed in 2.9.10+dfsg-6.7)
sid: resolved (fixed in 2.9.10+dfsg-6.7)
trixie: resolved (fixe
debian
CVE-2008-4225P4HIGHCVSS 7.8fixed in libxml2 2.6.32.dfsg-5 (bookworm)2008
CVE-2008-4225 [HIGH] CVE-2008-4225: libxml2 - Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context...
Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (infinite loop) via a large XML document.
Scope: local
bookworm: resolved (fixed in 2.6.32.dfsg-5)
bullseye: resolved (fixed in 2.6.32.dfsg-5)
forky: resolved (fixed in 2.6.32.dfsg-5)
sid: resolved (fixed in 2.6.32.dfsg-5)
trixie: resolved
debian
CVE-2015-7942P4MEDIUMCVSS 4.3fixed in libxml2 2.9.3+dfsg1-1 (bookworm)2015
CVE-2015-7942 [MEDIUM] CVE-2015-7942: libxml2 - The xmlParseConditionalSections function in parser.c in libxml2 does not properl...
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.
Scope: local
bookworm: resolved (fixed in 2.9.3+dfsg1
debian
CVE-2015-8241P4MEDIUMCVSS 6.4fixed in libxml2 2.9.3+dfsg1-1 (bookworm)2015
CVE-2015-8241 [MEDIUM] CVE-2015-8241: libxml2 - The xmlNextChar function in libxml2 2.9.2 does not properly check the state, whi...
The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
Scope: local
bookworm: resolved (fixed in 2.9.3+dfsg1-1)
bullseye: resolved (fixed in 2.9.3+dfsg1-1)
forky: resolve
debian
CVE-2015-7497P4MEDIUMCVSS 5.0fixed in libxml2 2.9.3+dfsg1-1 (bookworm)2015
CVE-2015-7497 [MEDIUM] CVE-2015-7497: libxml2 - Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in l...
Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.9.3+dfsg1-1)
bullseye: resolved (fixed in 2.9.3+dfsg1-1)
forky: resolved (fixed in 2.9.3+dfsg1-1)
sid: resolved (fixed in 2.9.3+dfsg1-1
debian
CVE-2021-3537P4MEDIUMCVSS 5.9fixed in libxml2 2.9.10+dfsg-6.6 (bookworm)2021
CVE-2021-3537 [MEDIUM] CVE-2021-3537: libxml2 - A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not...
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.
Scope: local
debian
CVE-2023-45322P4MEDIUMCVSS 6.5fixed in libxml2 2.9.14+dfsg-1.3~deb12u2 (bookworm)2023
CVE-2023-45322 [MEDIUM] CVE-2023-45322: libxml2 - libxml2 through 2.11.5 has a use-after-free that can only occur after a certain ...
libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."
Scope: local
bookworm: resolved (fixed in 2
debian
CVE-2016-9318P4MEDIUMCVSS 5.5fixed in libxml2 2.9.10+dfsg-2 (bookworm)2016
CVE-2016-9318 [MEDIUM] CVE-2016-9318: libxml2 - libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other produc...
libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.
Scope: local
bookworm: resolved (fixed in 2.9.10+dfsg-2)
debian
CVE-2015-7499P4MEDIUMCVSS 5.0fixed in libxml2 2.9.3+dfsg1-1 (bookworm)2015
CVE-2015-7499 [MEDIUM] CVE-2015-7499: libxml2 - Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before...
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.9.3+dfsg1-1)
bullseye: resolved (fixed in 2.9.3+dfsg1-1)
forky: resolved (fixed in 2.9.3+dfsg1-1)
sid: resolved (fixed in 2.9.3+df
debian
CVE-2015-1819P4LOWCVSS 5.0fixed in libxml2 2.9.2+really2.9.1+dfsg1-0.1 (bookworm)2015
CVE-2015-1819 [MEDIUM] CVE-2015-1819: libxml2 - The xmlreader in libxml allows remote attackers to cause a denial of service (me...
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
Scope: local
bookworm: resolved (fixed in 2.9.2+really2.9.1+dfsg1-0.1)
bullseye: resolved (fixed in 2.9.2+really2.9.1+dfsg1-0.1)
forky: resolved (fixed in 2.9.2+really2.9.1+dfsg1-0.1)
sid: resolved (
debian
CVE-2023-29469P4MEDIUMCVSS 6.5fixed in libxml2 2.9.14+dfsg-1.2 (bookworm)2023
CVE-2023-29469 [MEDIUM] CVE-2023-29469: libxml2 - An issue was discovered in libxml2 before 2.10.4. When hashing empty dict string...
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (no
debian
CVE-2011-2821P4LOWCVSS 7.5fixed in libxml2 2.7.8.dfsg-5 (bookworm)2011
CVE-2011-2821 [HIGH] CVE-2011-2821: libxml2 - Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.2...
Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
Scope: local
bookworm: resolved (fixed in 2.7.8.dfsg-5)
bullseye: resolved (fixed in 2.7.8.dfsg-5)
forky: resolved (fixed in 2.7.8.dfsg-5)
sid: resolved (fixed
debian
CVE-2018-14404P4LOWCVSS 6.5fixed in libxml2 2.9.10+dfsg-2 (bookworm)2018
CVE-2018-14404 [MEDIUM] CVE-2018-14404: libxml2 - A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEva...
A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the applicat
debian
CVE-2018-14567P4LOWCVSS 2.6fixed in libxml2 2.9.10+dfsg-2 (bookworm)2018
CVE-2018-14567 [LOW] CVE-2018-14567: libxml2 - libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial...
libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.
Scope: local
bookworm: resolved (fixed in 2.9.10+dfsg-2)
bullseye: resolved (fixed in 2.9.10+dfsg-2)
forky: res
debian
CVE-2014-3660P4MEDIUMCVSS 5.0fixed in libxml2 2.9.2+dfsg1-1 (bookworm)2014
CVE-2014-3660 [MEDIUM] CVE-2014-3660: libxml2 - parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even...
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.
Scope: local
bookworm: resolved
debian