Show filters
94 Total Results
Displaying 71-80 of 94
Sort by:
Attacker Value
Unknown
CVE-2015-7942
Disclosure Date: November 18, 2015 (last updated October 05, 2023)
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.
0
Attacker Value
Unknown
CVE-2015-8035
Disclosure Date: November 18, 2015 (last updated October 05, 2023)
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
0
Attacker Value
Unknown
CVE-2015-1819
Disclosure Date: August 14, 2015 (last updated October 05, 2023)
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
0
Attacker Value
Unknown
CVE-2015-3451
Disclosure Date: May 12, 2015 (last updated October 05, 2023)
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.
0
Attacker Value
Unknown
CVE-2014-3660
Disclosure Date: November 04, 2014 (last updated October 05, 2023)
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.
0
Attacker Value
Unknown
CVE-2013-2877
Disclosure Date: July 10, 2013 (last updated October 05, 2023)
parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state.
0
Attacker Value
Unknown
CVE-2013-1969
Disclosure Date: April 25, 2013 (last updated October 05, 2023)
Multiple use-after-free vulnerabilities in libxml2 2.9.0 and possibly other versions might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to the (1) htmlParseChunk and (2) xmldecl_done functions, as demonstrated by a buffer overflow in the xmlBufGetInputBase function.
0
Attacker Value
Unknown
CVE-2013-0338
Disclosure Date: April 25, 2013 (last updated October 05, 2023)
libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.
0
Attacker Value
Unknown
CVE-2012-0841
Disclosure Date: December 21, 2012 (last updated October 05, 2023)
libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.
0
Attacker Value
Unknown
CVE-2012-5134
Disclosure Date: November 28, 2012 (last updated October 05, 2023)
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.
0