cbcvebase.

Debian Libxml2 vulnerabilities

111 known vulnerabilities affecting debian/libxml2.

Total CVEs
111
CISA KEV
0
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL14HIGH38MEDIUM44LOW15

Vulnerabilities

Page 5 of 6
CVE-2015-8317P4MEDIUMCVSS 5.0fixed in libxml2 2.9.2+zdfsg1-4 (bookworm)2015
CVE-2015-8317 [MEDIUM] CVE-2015-8317: libxml2 - The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-... The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read. Scope: local bookworm: resolved (fixed in 2.9.2+zdfsg1-4) bullseye: resolved (fixed in 2.9.2+zdfsg1-4) fork
debian
CVE-2017-18258P4LOWCVSS 6.5fixed in libxml2 2.9.10+dfsg-2 (bookworm)2017
CVE-2017-18258 [MEDIUM] CVE-2017-18258: libxml2 - The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers ... The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file. Scope: local bookworm: resolved (fixed in 2.9.10+dfsg-2) bullseye: resolved (fixed in 2.9.10+dfsg-2) fo
debian
CVE-2015-8242P4MEDIUMCVSS 5.8fixed in libxml2 2.9.3+dfsg1-1 (bookworm)2015
CVE-2015-8242 [MEDIUM] CVE-2015-8242: libxml2 - The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser ... The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data. Scope: local bookworm: resolved (fixed in 2.9.3+dfsg1-1) bullseye: resolved (fixed in 2.9.3+d
debian
CVE-2016-1837P4MEDIUMCVSS 5.5fixed in libxml2 2.9.3+dfsg1-1.1 (bookworm)2016
CVE-2016-1837 [MEDIUM] CVE-2016-1837: libxml2 - Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2)... Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remote attackers to cause a denial of service via a crafted XML document. Scope: local bookworm: resolved (fixed in 2.9.3+d
debian
CVE-2016-1836P4MEDIUMCVSS 5.5fixed in libxml2 2.9.3+dfsg1-1.1 (bookworm)2016
CVE-2016-1836 [MEDIUM] CVE-2016-1836: libxml2 - Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 be... Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a crafted XML document. Scope: local bookworm: resolved (fixed in 2.9.3+dfsg1-1.1) bullseye: resolved (fixed in 2.9.3+
debian
CVE-2023-28484P4MEDIUMCVSS 6.5fixed in libxml2 2.9.14+dfsg-1.2 (bookworm)2023
CVE-2023-28484 [MEDIUM] CVE-2023-28484: libxml2 - In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a N... In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c. Scope: local bookworm: resolved (fixed in 2.9.14+dfsg-1.2) bullseye: resolved (fixed in 2.9.10+dfsg-6.7+deb11u4) forky: resolved (fixed in 2.9.14+dfsg-1.2) sid: resolved (fixe
debian
CVE-2026-1757P4LOWCVSS 6.2fixed in libxml2 2.15.2+dfsg-0.1 (forky)2026
CVE-2026-1757 [MEDIUM] CVE-2026-1757: libxml2 - A flaw was identified in the interactive shell of the xmllint utility, part of t... A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continu
debian
CVE-2012-2807P4MEDIUMCVSS 6.8fixed in libxml2 2.8.0+dfsg1-5 (bookworm)2012
CVE-2012-2807 [MEDIUM] CVE-2012-2807: libxml2 - Multiple integer overflows in libxml2, as used in Google Chrome before 20.0.1132... Multiple integer overflows in libxml2, as used in Google Chrome before 20.0.1132.43 and other products, on 64-bit Linux platforms allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. Scope: local bookworm: resolved (fixed in 2.8.0+dfsg1-5) bullseye: resolved (fixed in 2.8.0+dfsg1-5) forky: resolved (fixed
debian
CVE-2016-2073P4MEDIUMCVSS 6.5fixed in libxml2 2.9.3+dfsg1-1.1 (bookworm)2016
CVE-2016-2073 [MEDIUM] CVE-2016-2073: libxml2 - The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to... The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document. Scope: local bookworm: resolved (fixed in 2.9.3+dfsg1-1.1) bullseye: resolved (fixed in 2.9.3+dfsg1-1.1) forky: resolved (fixed in 2.9.3+dfsg1-1.1) sid: resolved (fixed in 2.9.3+dfsg1-1.1) trixie: resolved (fixed
debian
CVE-2015-7500P4MEDIUMCVSS 5.0fixed in libxml2 2.9.3+dfsg1-1 (bookworm)2015
CVE-2015-7500 [MEDIUM] CVE-2015-7500: libxml2 - The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dep... The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags. Scope: local bookworm: resolved (fixed in 2.9.3+dfsg1-1) bullseye: resolved (fixed in 2.9.3+dfsg1-1) forky: resolved (fixed in 2.9.3+df
debian
CVE-2023-39615P4MEDIUMCVSS 6.5fixed in libxml2 2.9.14+dfsg-1.3~deb12u2 (bookworm)2023
CVE-2023-39615 [MEDIUM] CVE-2023-39615: libxml2 - Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the ... Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML file. NOTE: the vendor's position is that the product does not support the legacy SAX1 interface with custom callbacks; there is a crash
debian
CVE-2011-3102P4MEDIUMCVSS 6.8fixed in libxml2 2.7.8.dfsg-9.1 (bookworm)2011
CVE-2011-3102 [MEDIUM] CVE-2011-3102: libxml2 - Off-by-one error in libxml2, as used in Google Chrome before 19.0.1084.46 and ot... Off-by-one error in libxml2, as used in Google Chrome before 19.0.1084.46 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors. Scope: local bookworm: resolved (fixed in 2.7.8.dfsg-9.1) bullseye: resolved (fixed in 2.7.8.dfsg-9.1) forky: resolved (fixed in 2.7.8.d
debian
CVE-2011-2834P4LOWCVSS 6.8fixed in libxml2 2.7.8.dfsg-5 (bookworm)2011
CVE-2011-2834 [MEDIUM] CVE-2011-2834: libxml2 - Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.1... Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling. Scope: local bookworm: resolved (fixed in 2.7.8.dfsg-5) bullseye: resolved (fixed in 2.7.8.dfsg-5) forky: resolved (fixed in 2.7.8.dfsg-5) sid: resolv
debian
CVE-2025-9714P4MEDIUMCVSS 6.2fixed in libxml2 2.9.14+dfsg-1.3~deb12u5 (bookworm)2025
CVE-2025-9714 [MEDIUM] CVE-2025-9714: libxml2 - Uncontrolled recursion in XPath evaluation in libxml2 up to and including versio... Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were calle
debian
CVE-2008-3281P4MEDIUMCVSS 6.5fixed in libxml2 2.6.32.dfsg-3 (bookworm)2008
CVE-2008-3281 [MEDIUM] CVE-2008-3281: libxml2 - libxml2 2.6.32 and earlier does not properly detect recursion during entity expa... libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document. Scope: local bookworm: resolved (fixed in 2.6.32.dfsg-3) bullseye: resolved (fixed in 2.6.32.dfsg-3) forky: resolved (fixed in 2.6.3
debian
CVE-2013-2877P4MEDIUMCVSS 5.0fixed in libxml2 2.9.1+dfsg1-1 (bookworm)2013
CVE-2013-2877 [MEDIUM] CVE-2013-2877: libxml2 - parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 a... parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state. Scope: local bookworm: resolved (fixed in 2.9.1+dfsg1-1) bullseye: resolved (fixed in 2.9.1+
debian
CVE-2016-1833P4MEDIUMCVSS 5.5fixed in libxml2 2.9.3+dfsg1-1.1 (bookworm)2016
CVE-2016-1833 [MEDIUM] CVE-2016-1833: libxml2 - The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS befor... The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. Scope: local bookworm: resolved (fixed in 2.9.3+dfsg1-1.1) bullseye: resolved (fixed in 2.9.3+dfsg1-1.
debian
CVE-2016-3709P4MEDIUMCVSS 6.1fixed in libxml2 2.9.12+dfsg-3 (bookworm)2016
CVE-2016-3709 [MEDIUM] CVE-2016-3709: libxml2 - Possible cross-site scripting vulnerability in libxml after commit 960f0e2. Possible cross-site scripting vulnerability in libxml after commit 960f0e2. Scope: local bookworm: resolved (fixed in 2.9.12+dfsg-3) bullseye: resolved (fixed in 2.9.10+dfsg-6.7+deb11u5) forky: resolved (fixed in 2.9.12+dfsg-3) sid: resolved (fixed in 2.9.12+dfsg-3) trixie: resolved (fixed in 2.9.12+dfsg-3)
debian
CVE-2012-0841P4MEDIUMCVSS 5.0fixed in libxml2 2.7.8.dfsg-8 (bookworm)2012
CVE-2012-0841 [MEDIUM] CVE-2012-0841: libxml2 - libxml2 before 2.8.0 computes hash values without restricting the ability to tri... libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data. Scope: local bookworm: resolved (fixed in 2.7.8.dfsg-8) bullseye: resolved (fixed in 2.7.8.dfsg-8) forky: resolved (fixed in 2.7.8.dfsg-8) sid:
debian
CVE-2009-2416P4LOWCVSS 6.5fixed in libxml2 2.7.3.dfsg-2.1 (bookworm)2009
CVE-2009-2416 [MEDIUM] CVE-2009-2416: libxml2 - Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.2... Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework. Scope: local bookworm: resolved (fixe
debian
Debian Libxml2 vulnerabilities | cvebase