Xmlsoft / Libxml2
115 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-86144 | libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parseFlags propagation. | HIGH | 7.8 | Sep 5, 2026 |
| CVE-2026-86143 | libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks | HIGH | 7.3 | Sep 5, 2026 |
| CVE-2026-86142 | libxml2: libxml2: Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturation | HIGH | 7.8 | Sep 5, 2026 |
| CVE-2026-86141 | libxml2: libxml2: Denial of Service due to NULL pointer dereference in xmlRegNewParserCtxt | LOW | 3.3 | Sep 5, 2026 |
| CVE-2026-86140 | libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements | HIGH | 8.0 | Sep 5, 2026 |
| CVE-2026-86139 | libxml2: libxml2: Integer overflow in xmlURIEscapeStr may lead to arbitrary code execution | HIGH | 7.8 | Sep 5, 2026 |
| CVE-2026-86138 | libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow | HIGH | 7.8 | Sep 5, 2026 |
| CVE-2026-86137 | libxml2: libxml2: Denial of Service via out-of-bounds read in xmlFAParsePosCharGroup | MEDIUM | 6.1 | Sep 5, 2026 |
| CVE-2026-11979 | Stack-Based Buffer Overflow in libxml2 | LOW | 1.8 | Jun 29, 2026 |
| CVE-2026-6653 | libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling | HIGH | 7.0 | Jun 22, 2026 |
| CVE-2026-6732 | Libxml2: libxml2: denial of service via crafted xsd-validated document | HIGH | 7.5 | Apr 23, 2026 |
| CVE-2026-0992 | Libxml2: libxml2: denial of service via crafted xml catalogs | LOW | 2.9 | Jan 15, 2026 |
| CVE-2026-0989 | Libxml2: unbounded relaxng include recursion leading to stack overflow | LOW | 3.7 | Jan 15, 2026 |
| CVE-2026-0990 | Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing | MEDIUM | 5.9 | Jan 15, 2026 |
| CVE-2025-9714 | Stack overflow in libxml2 | MEDIUM | 6.2 | Sep 10, 2025 |
| CVE-2025-8732 | libxml2 xmlcatalog xmlParseSGMLCatalog recursion | MEDIUM | 4.8 | Aug 8, 2025 |
| CVE-2025-6170 | Libxml2: stack buffer overflow in xmllint interactive shell command handling | LOW | 2.5 | Jun 16, 2025 |
| CVE-2025-6021 | Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2 | HIGH | 7.5 | Jun 12, 2025 |
| CVE-2025-32415 | libxml2: Out-of-bounds Read in xmlSchemaIDCFillNodeTables | HIGH | 7.5 | Apr 17, 2025 |
| CVE-2025-32414 | libxml2: Out-of-Bounds Read in libxml2 | HIGH | 7.5 | Apr 8, 2025 |
| CVE-2025-27113 | libxml2: NULL Pointer Dereference in libxml2 xmlPatMatch | HIGH | 7.5 | Feb 18, 2025 |
| CVE-2025-24928 | libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2 | HIGH | 7.8 | Feb 18, 2025 |
| CVE-2024-56171 | libxml2: Use-After-Free in libxml2 | CRITICAL | 9.8 | Feb 18, 2025 |
| CVE-2022-49043 | libxml: use-after-free in xmlXIncludeAddNode | HIGH | 8.1 | Jan 26, 2025 |
| CVE-2024-40896 | libxml2: XXE vulnerability | CRITICAL | 9.1 | Dec 23, 2024 |
Showing 1 to 25 of 115 CVEs