Xmlsoft / Libxslt
25 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-7424 | Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes | HIGH | 7.5 | Jul 10, 2025 |
| CVE-2025-24855 | libxslt: Use-After-Free in libxslt numbers.c | HIGH | 7.8 | Mar 14, 2025 |
| CVE-2024-55549 | libxslt: Use-After-Free in libxslt (xsltGetInheritedNsList) | HIGH | 7.8 | Mar 14, 2025 |
| CVE-2022-29824 | libxml2: integer overflows in xmlBuf and xmlBuffer lead to out-of-bounds write | HIGH | 7.4 | May 3, 2022 |
| CVE-2021-30560 | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | HIGH | 8.8 | Aug 3, 2021 |
| CVE-2019-5815 | chromium-browser: Heap buffer overflow in Blink | HIGH | 7.5 | Dec 11, 2019 |
| CVE-2019-18197 | libxslt: use after free in xsltCopyText in transform.c could lead to information disclosure | HIGH | 7.5 | Oct 18, 2019 |
| CVE-2019-13118 | libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character | MEDIUM | 5.3 | Jul 1, 2019 |
| CVE-2019-13117 | libxslt: an xsl number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers | MEDIUM | 5.3 | Jul 1, 2019 |
| CVE-2019-11068 | libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL | CRITICAL | 9.8 | Apr 10, 2019 |
| CVE-2017-5029 | chromium-browser: integer overflow in libxslt | HIGH | 8.8 | Apr 24, 2017 |
| CVE-2015-9019 | libxslt: math.random() in xslt uses unseeded randomness | MEDIUM | 5.3 | Apr 5, 2017 |
| CVE-2016-4610 | libxslt: Invalid memory access leading to DoS at exsltDynMapFunction() | CRITICAL | 9.8 | Jul 22, 2016 |
| CVE-2016-4609 | libxslt: Out-of-bounds read at xmlGetLineNoInternal() | CRITICAL | 9.8 | Jul 22, 2016 |
| CVE-2016-4608 | libxslt: stack-based buffer overflow at exsltDateFormat() | CRITICAL | 9.8 | Jul 22, 2016 |
| CVE-2016-4607 | libxslt: allows remote attacker to cause denial of service | CRITICAL | 9.8 | Jul 22, 2016 |
| CVE-2016-1684 | chromium-browser: integer overflow in libxslt | HIGH | 7.5 | Jun 5, 2016 |
| CVE-2016-1683 | chromium-browser: out-of-bounds access in libxslt | HIGH | 7.5 | Jun 5, 2016 |
| CVE-2015-7995 | libxslt: Type confusion may cause DoS | MEDIUM | 5.0 | Nov 17, 2015 |
| CVE-2013-4520 | libxslt: DoS when reading unexpected DTD nodes in XSLT in versions prior to 1.1.25 | MEDIUM | 4.3 | Dec 14, 2013 |
| CVE-2012-6139 | libxslt: two DoS issues fixed in 1.1.28 | MEDIUM | 5.0 | Apr 12, 2013 |
| CVE-2012-2870 | libxslt: Use-after-free when processing an invalid XPath expression | MEDIUM | 4.3 | Aug 31, 2012 |
| CVE-2011-3970 | libxslt: Out-of-bounds read when parsing certain patterns | MEDIUM | 4.3 | Feb 9, 2012 |
| CVE-2011-1202 | libxslt: Heap address leak in XLST | MEDIUM | 4.3 | Mar 11, 2011 |
| CVE-2008-2935 | libxslt: buffer overflow in libexslt RC4 encryption/decryption functions | HIGH | 7.5 | Aug 1, 2008 |
Showing 1 to 25 of 25 CVEs