rpm package
almalinux/libxml2
pkg:rpm/almalinux/libxml2
Vulnerabilities (28)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-34459 | Hig | 7.5 | < 2.9.7-21.el8_10.5 | 2.9.7-21.el8_10.5 | May 14, 2024 | An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c. | |
| CVE-2024-25062 | Hig | 7.5 | < 2.9.13-6.el9_4 | 2.9.13-6.el9_4 | Feb 4, 2024 | An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free. | |
| CVE-2023-39615 | Med | 6.5 | < 2.9.13-5.el9_3 | 2.9.13-5.el9_3 | Aug 29, 2023 | Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML file. NOTE: the vendor's position is that the prod | |
| CVE-2023-29469 | Med | 6.5 | < 2.9.13-3.el9_2.1 | 2.9.13-3.el9_2.1 | Apr 24, 2023 | An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there | |
| CVE-2023-28484 | Med | 6.5 | < 2.9.13-3.el9_2.1 | 2.9.13-3.el9_2.1 | Apr 24, 2023 | In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c. | |
| CVE-2022-40304 | Hig | 7.8 | < 2.9.7-15.el8_7.1 | 2.9.7-15.el8_7.1 | Nov 23, 2022 | An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. | |
| CVE-2022-40303 | Hig | 7.5 | < 2.9.7-15.el8_7.1 | 2.9.7-15.el8_7.1 | Nov 23, 2022 | An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmen | |
| CVE-2016-3709 | Med | 6.1 | < 2.9.7-15.el8 | 2.9.7-15.el8 | Jul 28, 2022 | Possible cross-site scripting vulnerability in libxml after commit 960f0e2. |
- affected < 2.9.7-21.el8_10.5fixed 2.9.7-21.el8_10.5
An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.
- affected < 2.9.13-6.el9_4fixed 2.9.13-6.el9_4
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
- affected < 2.9.13-5.el9_3fixed 2.9.13-5.el9_3
Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML file. NOTE: the vendor's position is that the prod
- affected < 2.9.13-3.el9_2.1fixed 2.9.13-3.el9_2.1
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there
- affected < 2.9.13-3.el9_2.1fixed 2.9.13-3.el9_2.1
In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.
- affected < 2.9.7-15.el8_7.1fixed 2.9.7-15.el8_7.1
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
- affected < 2.9.7-15.el8_7.1fixed 2.9.7-15.el8_7.1
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmen
- affected < 2.9.7-15.el8fixed 2.9.7-15.el8
Possible cross-site scripting vulnerability in libxml after commit 960f0e2.
Page 2 of 2