cbcvebase.

Debian Libxslt vulnerabilities

30 known vulnerabilities affecting debian/libxslt.

Total CVEs
30
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH13MEDIUM7LOW6

Vulnerabilities

Page 1 of 2
CVE-2008-2935P3HIGHCVSS 7.5PoCfixed in libxslt 1.1.24-2 (bookworm)2008
CVE-2008-2935 [HIGH] CVE-2008-2935: libxslt - Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoR... Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input." Scope: local b
debian
CVE-2008-1767P3HIGHCVSS 7.5PoCfixed in libxslt 1.1.24-1 (bookworm)2008
CVE-2008-1767 [HIGH] CVE-2008-1767: libxslt - Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent a... Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps. Scope: local bookworm: resolved (fixed in 1.1.24-1) bullseye: resolved (fixed in 1.1.24-1)
debian
CVE-2021-30560P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30560 [HIGH] CVE-2021-30560: chromium - Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a r... Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed
debian
CVE-2019-11068P3CRITICALCVSS 9.8fixed in libxslt 1.1.32-2.1 (bookworm)2019
CVE-2019-11068 [CRITICAL] CVE-2019-11068: libxslt - libxslt through 1.1.33 allows bypass of a protection mechanism because callers o... libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded. Scope: local bookworm: resolved (fixed in 1.1.32-2.1) bullseye: resolved (fixed in 1.1.32-2.1)
debian
CVE-2016-4609P3CRITICALCVSS 9.8fixed in libxslt 1.1.29-1 (bookworm)2016
CVE-2016-4609 [CRITICAL] CVE-2016-4609: libxslt - libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on ... libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-4608, CVE-
debian
CVE-2016-4610P3CRITICALCVSS 9.8fixed in libxslt 1.1.29-1 (bookworm)2016
CVE-2016-4610 [CRITICAL] CVE-2016-4610: libxslt - libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on ... libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-4608, CVE-
debian
CVE-2016-4608P3CRITICALCVSS 9.8fixed in libxslt 1.1.29-1 (bookworm)2016
CVE-2016-4608 [CRITICAL] CVE-2016-4608: libxslt - libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on ... libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-4609, CVE-
debian
CVE-2016-4738P3HIGHCVSS 8.8fixed in libxslt 1.1.29-2 (bookworm)2016
CVE-2016-4738 [HIGH] CVE-2016-4738: libxslt - libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS b... libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. Scope: local bookworm: resolved (fixed in 1.1.29-2) bullseye: resolved (fixed in 1.1.29-2) forky: resolved (fixed in 1.1.29-2) sid: resolved (fixed in 1.1.29-2
debian
CVE-2016-1841P3HIGHCVSS 8.8fixed in libxslt 1.1.29-1 (bookworm)2016
CVE-2016-1841 [HIGH] CVE-2016-1841: libxslt - libxslt, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2... libxslt, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. Scope: local bookworm: resolved (fixed in 1.1.29-1) bullseye: resolved (fixed in 1.1.29-1) forky: resolved (fixed in 1.1.29-1) sid: resol
debian
CVE-2017-5029P3HIGHCVSS 8.8fixed in libxslt 1.1.29-2.1 (bookworm)2017
CVE-2017-5029 [HIGH] CVE-2017-5029: libxslt - The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blin... The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. Scope: local bookworm: resolv
debian
CVE-2019-18197P3HIGHCVSS 7.5fixed in libxslt 1.1.32-2.2 (bookworm)2019
CVE-2019-18197 [HIGH] CVE-2019-18197: libxslt - In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset... In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed. Scope: local bookworm: resolved (fixed in 1.1.32-2.2) bullseye:
debian
CVE-2025-7424P3HIGHCVSS 7.5fixed in libxslt 1.1.35-1+deb12u2 (bookworm)2025
CVE-2025-7424 [HIGH] CVE-2025-7424: libxslt - A flaw was found in the libxslt library. The same memory field, psvi, is used fo... A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior. Scope: local bookworm: resolved (fixed in
debian
CVE-2024-55549P3HIGHCVSS 7.8fixed in libxslt 1.1.35-1+deb12u1 (bookworm)2024
CVE-2024-55549 [HIGH] CVE-2024-55549: libxslt - xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue relat... xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes. Scope: local bookworm: resolved (fixed in 1.1.35-1+deb12u1) bullseye: resolved (fixed in 1.1.34-4+deb11u2) forky: resolved (fixed in 1.1.35-1.2) sid: resolved (fixed in 1.1.35-1.2) trixie: resolved (fixed in 1.1.35-1.2)
debian
CVE-2025-24855P3HIGHCVSS 7.8fixed in libxslt 1.1.35-1+deb12u1 (bookworm)2025
CVE-2025-24855 [HIGH] CVE-2025-24855: libxslt - numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath... numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal. Scope: local bookworm: resolved (fixed in 1.1.35-1+deb12u1) bullseye: resolved (fixed in
debian
CVE-2019-5815P3HIGHCVSS 7.5fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5815 [HIGH] CVE-2019-5815: chromium - Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could... Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data. Scope: local bookworm: resolved (fixed in 74.0.3729.108-1) bullseye: resolved (fixed in 74.0.3729.108-1) forky: resolved (fixed in 74.0.3729.108-1) sid: resolved (fixed in 74.0.3729.108-1) trixie: resolved (fixe
debian
CVE-2016-1683P3HIGHCVSS 7.5fixed in libxslt 1.1.29-1 (bookworm)2016
CVE-2016-1683 [HIGH] CVE-2016-1683: libxslt - numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63... numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bounds heap memory access) or possibly have unspecified other impact via a crafted document. Scope: local bookworm: resolved (fixed in 1.1.29-1) bullseye: resolved (fixed in 1.1.29-1) forky: re
debian
CVE-2016-1684P4HIGHCVSS 7.5fixed in libxslt 1.1.29-1 (bookworm)2016
CVE-2016-1684 [HIGH] CVE-2016-1684: libxslt - numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63... numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document. Scope: local bookworm: resolved (fixed in 1.1.29-1) bullseye: resolve
debian
CVE-2019-13117P4LOWCVSS 5.3fixed in libxslt 1.1.32-2.1 (bookworm)2019
CVE-2019-13117 [MEDIUM] CVE-2019-13117: libxslt - In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could ... In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character. Scope: local bookworm: resolved (fixed in 1.1.32-2.1) bullseye: resolved (fixed in 1.1.32
debian
CVE-2023-40403P4MEDIUMCVSS 6.5fixed in libxslt 1.1.35-1+deb12u2 (bookworm)2023
CVE-2023-40403 [MEDIUM] CVE-2023-40403: libxslt - The issue was addressed with improved memory handling. This issue is fixed in ma... The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may disclose sensitive information. Scope: local bookworm: resolved (fixed in 1.1.35-1+deb12u2) bullseye: resolved (fixed in 1.1.34-4+deb1
debian
CVE-2019-13118P4LOWCVSS 5.3fixed in libxslt 1.1.32-2.1 (bookworm)2019
CVE-2019-13118 [MEDIUM] CVE-2019-13118: libxslt - In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:num... In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data. Scope: local bookworm: resolved (fixed in 1.1.32-2.1) bullseye: resolved (fixed in 1.1.32-2.1) forky: resolved (fixed in
debian
Debian Libxslt vulnerabilities | cvebase