Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2014-3660

Disclosure Date: November 04, 2014 (last updated October 05, 2023)
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.
0
Attacker Value
Unknown

CVE-2013-2877

Disclosure Date: July 10, 2013 (last updated October 05, 2023)
parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state.
0
Attacker Value
Unknown

CVE-2013-0338

Disclosure Date: April 25, 2013 (last updated October 05, 2023)
libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.
0
Attacker Value
Unknown

CVE-2012-0841

Disclosure Date: December 21, 2012 (last updated October 05, 2023)
libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.
0
Attacker Value
Unknown

CVE-2012-5134

Disclosure Date: November 28, 2012 (last updated October 05, 2023)
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.
0
Attacker Value
Unknown

CVE-2004-0110

Disclosure Date: March 15, 2004 (last updated October 03, 2023)
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.
0