cbcvebase.

Debian Libxml2 vulnerabilities

111 known vulnerabilities affecting debian/libxml2.

Total CVEs
111
CISA KEV
0
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL14HIGH38MEDIUM44LOW15

Vulnerabilities

Page 6 of 6
CVE-2015-7941P4MEDIUMCVSS 4.3fixed in libxml2 2.9.2+really2.9.1+dfsg1-0.1 (bookworm)2015
CVE-2015-7941 [MEDIUM] CVE-2015-7941: libxml2 - libxml2 2.9.2 does not properly stop parsing invalid input, which allows context... libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities. Scope: local bookworm: resolved (fixed in 2.9.2
debian
CVE-2017-5969P4MEDIUMCVSS 4.7fixed in libxml2 2.9.4+dfsg1-5.1 (bookworm)2017
CVE-2017-5969 [MEDIUM] CVE-2017-5969: libxml2 - libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a den... libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser. Scope: local bookworm: resolved (fixed in 2.9.4+dfsg1-5.1) b
debian
CVE-2013-0338P4MEDIUMCVSS 4.3fixed in libxml2 2.8.0+dfsg1-7+nmu1 (bookworm)2013
CVE-2013-0338 [MEDIUM] CVE-2013-0338: libxml2 - libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial o... libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity. Scope: local bookworm: resolved (fixed in 2.8.0+dfsg1-7+nmu1) bullseye: resolved
debian
CVE-2011-3905P4MEDIUMCVSS 5.0fixed in libxml2 2.7.8.dfsg-5.1 (bookworm)2011
CVE-2011-3905 [MEDIUM] CVE-2011-3905: libxml2 - libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to... libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. Scope: local bookworm: resolved (fixed in 2.7.8.dfsg-5.1) bullseye: resolved (fixed in 2.7.8.dfsg-5.1) forky: resolved (fixed in 2.7.8.dfsg-5.1) sid: resolved (fixed in 2.7.8.dfsg-5.1) trixie: resolved (fixed in 2.7
debian
CVE-2009-2414P4MEDIUMCVSS 4.3fixed in libxml2 2.7.3.dfsg-2.1 (bookworm)2009
CVE-2009-2414 [MEDIUM] CVE-2009-2414: libxml2 - Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2... Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework. Scope: local bookworm: resolved (fi
debian
CVE-2015-8035P4LOWCVSS 2.6fixed in libxml2 2.9.3+dfsg1-1 (bookworm)2015
CVE-2015-8035 [LOW] CVE-2015-8035: libxml2 - The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect comp... The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data. Scope: local bookworm: resolved (fixed in 2.9.3+dfsg1-1) bullseye: resolved (fixed in 2.9.3+dfsg1-1) forky: resolved (fixed in 2.9.3+dfsg1-1) sid: resolved (fixed in 2.
debian
CVE-2007-6284P4MEDIUMCVSS 5.0fixed in libxml2 2.6.30.dfsg-3.1 (bookworm)2007
CVE-2007-6284 [MEDIUM] CVE-2007-6284: libxml2 - The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent at... The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences. Scope: local bookworm: resolved (fixed in 2.6.30.dfsg-3.1) bullseye: resolved (fixed in 2.6.30.dfsg-3.1) forky: resolved (fixed in 2.6.30.dfsg-3.1) sid: resolved (fixed in 2.6.30.dfsg-3.1) tr
debian
CVE-2010-4008P4MEDIUMCVSS 4.3fixed in libxml2 2.7.8.dfsg-1 (bookworm)2010
CVE-2010-4008 [MEDIUM] CVE-2010-4008: libxml2 - libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5... libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document. Scope: local bookworm: resolved (fixed in 2.7.
debian
CVE-2026-0989P4LOWCVSS 3.7fixed in libxml2 2.15.2+dfsg-0.1 (forky)2026
CVE-2026-0989 [LOW] CVE-2026-0989: libxml2 - A flaw was identified in the RelaxNG parser of libxml2 related to how external s... A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-se
debian
CVE-2026-0992P4LOWCVSS 2.9fixed in libxml2 2.15.2+dfsg-0.1 (forky)2026
CVE-2026-0992 [LOW] CVE-2026-0992: libxml2 - A flaw was found in the libxml2 library. This uncontrolled resource consumption ... A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and
debian
CVE-2025-6170P4LOWCVSS 2.5fixed in libxml2 2.9.14+dfsg-1.3~deb12u3 (bookworm)2025
CVE-2025-6170 [LOW] CVE-2025-6170: libxml2 - A flaw was found in the interactive shell of the xmllint command-line tool, used... A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections. Scope: local bookworm: resolved (fixed
debian
Debian Libxml2 vulnerabilities | cvebase