Show filters
125 Total Results
Displaying 31-40 of 125
Sort by:
Attacker Value
Unknown

CVE-2016-1836

Disclosure Date: May 20, 2016 (last updated November 25, 2024)
Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a crafted XML document.
0
Attacker Value
Unknown

CVE-2016-1835

Disclosure Date: May 20, 2016 (last updated November 25, 2024)
Use-after-free vulnerability in the xmlSAX2AttributeNs function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2 and OS X before 10.11.5, allows remote attackers to cause a denial of service via a crafted XML document.
0
Attacker Value
Unknown

CVE-2016-1834

Disclosure Date: May 20, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
0
Attacker Value
Unknown

CVE-2016-1762

Disclosure Date: March 24, 2016 (last updated November 25, 2024)
The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
0
Attacker Value
Unknown

CVE-2015-7500

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
0
Attacker Value
Unknown

CVE-2015-7499

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-5312

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
0
Attacker Value
Unknown

CVE-2015-7942

Disclosure Date: November 18, 2015 (last updated October 05, 2023)
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.
0
Attacker Value
Unknown

CVE-2015-8035

Disclosure Date: November 18, 2015 (last updated October 05, 2023)
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
0
Attacker Value
Unknown

CVE-2015-1819

Disclosure Date: August 14, 2015 (last updated October 05, 2023)
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
0