Debian Libxslt vulnerabilities
30 known vulnerabilities affecting debian/libxslt.
Total CVEs
30
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH13MEDIUM7LOW6
Vulnerabilities
Page 2 of 2
CVE-2012-2871P4MEDIUMCVSS 6.8fixed in libxslt 1.1.26-14 (bookworm)2012
CVE-2012-2871 [MEDIUM] CVE-2012-2871: libxslt - libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, doe...
libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document, related to the _xmlNs data structure in include/libxml/tree.h.
Scope: local
debian
CVE-2012-2893P4MEDIUMCVSS 6.8fixed in libxslt 1.1.26-14 (bookworm)2012
CVE-2012-2893 [MEDIUM] CVE-2012-2893: libxslt - Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229....
Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms.
Scope: local
bookworm: resolved (fixed in 1.1.26-14)
bullseye: resolved (fixed in 1.1.26-14)
forky: resolved (fixed in 1.1.26-14)
sid: resolved (fixed
debian
CVE-2015-7995P4MEDIUMCVSS 5.0fixed in libxslt 1.1.28-2.1 (bookworm)2015
CVE-2015-7995 [MEDIUM] CVE-2015-7995: libxslt - The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check i...
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
Scope: local
bookworm: resolved (fixed in 1.1.28-2.1)
bullseye: resolved (fixed in 1.1.28-2.1)
forky: resolved (fixed in 1.1.28-2.1)
sid: reso
debian
CVE-2012-6139P4MEDIUMCVSS 5.0fixed in libxslt 1.1.26-14.1 (bookworm)2012
CVE-2012-6139 [MEDIUM] CVE-2012-6139: libxslt - libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL...
libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized variable to the xsltDocumentFunction function in functions.c.
Scope: local
bookworm: resolved (fixed in 1.1.26-14.1)
bullseye: resolved (fixed in 1.1.26
debian
CVE-2012-2825P4LOWCVSS 5.0fixed in libxslt 1.1.26-13 (bookworm)2012
CVE-2012-2825 [MEDIUM] CVE-2012-2825: libxslt - The XSL implementation in Google Chrome before 20.0.1132.43 allows remote attack...
The XSL implementation in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.1.26-13)
bullseye: resolved (fixed in 1.1.26-13)
forky: resolved (fixed in 1.1.26-13)
sid: resolved (fixed in 1.1.26-13)
trixie: resolved (fixed in 1.1.26-13)
debian
CVE-2011-1202P4LOWCVSS 4.3fixed in libxslt 1.1.26-7 (bookworm)2011
CVE-2011-1202 [MEDIUM] CVE-2011-1202: libxslt - The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier...
The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
Scope: local
bookworm: resolved (fixed in 1.1.2
debian
CVE-2025-10911P4MEDIUMCVSS 5.5fixed in libxslt 1.1.43-0.3 (forky)2025
CVE-2025-10911 [MEDIUM] CVE-2025-10911: libxslt - A use-after-free vulnerability was found in libxslt while parsing xsl nodes that...
A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.1.43-0.3)
sid: resolved (fixed in 1.1.43-0.3)
trixie: open
debian
CVE-2011-3970P4LOWCVSS 4.3fixed in libxslt 1.1.26-11 (bookworm)2011
CVE-2011-3970 [MEDIUM] CVE-2011-3970: libxslt - libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to...
libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.1.26-11)
bullseye: resolved (fixed in 1.1.26-11)
forky: resolved (fixed in 1.1.26-11)
sid: resolved (fixed in 1.1.26-11)
trixie: resolved (fixed in 1.1.26-11)
debian
CVE-2012-2870P4MEDIUMCVSS 4.3fixed in libxslt 1.1.26-14 (bookworm)2012
CVE-2012-2870 [MEDIUM] CVE-2012-2870: libxslt - libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does n...
libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/pattern.c and (2) th
debian
CVE-2025-11731P4LOWCVSS 3.1fixed in libxslt 1.1.43-0.3 (forky)2025
CVE-2025-11731 [LOW] CVE-2025-11731: libxslt - A flaw was found in the exsltFuncResultComp() function of libxslt, which handles...
A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead
debian
← Previous2 / 2