Show filters
113 Total Results
Displaying 91-100 of 113
Sort by:
Attacker Value
Unknown
CVE-2013-1969
Disclosure Date: April 25, 2013 (last updated October 05, 2023)
Multiple use-after-free vulnerabilities in libxml2 2.9.0 and possibly other versions might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to the (1) htmlParseChunk and (2) xmldecl_done functions, as demonstrated by a buffer overflow in the xmlBufGetInputBase function.
0
Attacker Value
Unknown
CVE-2013-0338
Disclosure Date: April 25, 2013 (last updated October 05, 2023)
libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.
0
Attacker Value
Unknown
CVE-2012-6139
Disclosure Date: April 12, 2013 (last updated October 05, 2023)
libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized variable to the xsltDocumentFunction function in functions.c.
0
Attacker Value
Unknown
CVE-2012-0841
Disclosure Date: December 21, 2012 (last updated October 05, 2023)
libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.
0
Attacker Value
Unknown
CVE-2012-5134
Disclosure Date: November 28, 2012 (last updated October 05, 2023)
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.
0
Attacker Value
Unknown
CVE-2012-2870
Disclosure Date: August 31, 2012 (last updated October 05, 2023)
libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/pattern.c and (2) the xsltGenerateIdFunction function in libxslt/functions.c.
0
Attacker Value
Unknown
CVE-2012-2871
Disclosure Date: August 31, 2012 (last updated October 05, 2023)
libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document, related to the _xmlNs data structure in include/libxml/tree.h.
0
Attacker Value
Unknown
CVE-2011-3970
Disclosure Date: February 09, 2012 (last updated October 04, 2023)
libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-1944
Disclosure Date: September 02, 2011 (last updated October 04, 2023)
Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.
0
Attacker Value
Unknown
CVE-2011-1202
Disclosure Date: March 11, 2011 (last updated October 04, 2023)
The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
0