VYPR

rpm package

suse/libxml2&distro=SUSE Linux Enterprise Server 12

pkg:rpm/suse/libxml2&distro=SUSE%20Linux%20Enterprise%20Server%2012

Vulnerabilities (29)

  • CVE-2015-7500Dec 15, 2015
    affected < 2.9.1-13.1fixed 2.9.1-13.1

    The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.

  • CVE-2015-7499Dec 15, 2015
    affected < 2.9.1-13.1fixed 2.9.1-13.1

    Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.

  • CVE-2015-7498Dec 15, 2015
    affected < 2.9.1-13.1fixed 2.9.1-13.1

    Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.

  • CVE-2015-7497Dec 15, 2015
    affected < 2.9.1-13.1fixed 2.9.1-13.1

    Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.

  • CVE-2015-5312Dec 15, 2015
    affected < 2.9.1-13.1fixed 2.9.1-13.1

    The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.

  • CVE-2015-8035Nov 18, 2015
    affected < 2.9.1-13.1fixed 2.9.1-13.1

    The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

  • CVE-2015-7942Nov 18, 2015
    affected < 2.9.1-13.1fixed 2.9.1-13.1

    The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different

  • CVE-2015-7941Nov 18, 2015
    affected < 2.9.1-13.1fixed 2.9.1-13.1

    libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as

  • CVE-2015-1819Aug 14, 2015
    affected < 2.9.1-13.1fixed 2.9.1-13.1

    The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.

Page 2 of 2