Search CVE reports


Toggle filters

11 – 20 of 126 results


CVE-2024-56171

Medium priority
Fixed

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema...

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-40896

Medium priority
Fixed

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This...

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-34459

Low priority

Some fixes available 6 of 7

An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-25062

Medium priority
Fixed

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to...

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Fixed Fixed Fixed
Show less packages

CVE-2023-45322

Medium priority
Not affected

libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to...

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Not affected Not affected Not affected
Show less packages

CVE-2023-39615

Medium priority
Not affected

Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML...

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Not affected Not affected Not affected
Show less packages

CVE-2023-29469

Medium priority
Fixed

An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as...

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Fixed Fixed Fixed
Show less packages

CVE-2023-28484

Medium priority
Fixed

In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Fixed Fixed Fixed
Show less packages

CVE-2022-49043

Medium priority
Fixed

xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Fixed Fixed Fixed Fixed
Show less packages

CVE-2022-40304

Medium priority
Fixed

An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.

1 affected package

libxml2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxml2 Fixed Fixed Fixed
Show less packages