rpm package
suse/libxml2-python&distro=SUSE Linux Enterprise Desktop 11 SP3
pkg:rpm/suse/libxml2-python&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3
Vulnerabilities (12)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2015-8710 | Cri | 9.8 | < 2.7.6-0.37.4 | 2.7.6-0.37.4 | Apr 11, 2016 | The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed HTML comment. | |
| CVE-2015-8317 | — | < 2.7.6-0.34.4 | 2.7.6-0.34.4 | Dec 15, 2015 | The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read. | ||
| CVE-2015-8242 | — | < 2.7.6-0.34.4 | 2.7.6-0.34.4 | Dec 15, 2015 | The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data. | ||
| CVE-2015-8241 | — | < 2.7.6-0.34.4 | 2.7.6-0.34.4 | Dec 15, 2015 | The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data. | ||
| CVE-2015-7500 | — | < 2.7.6-0.34.4 | 2.7.6-0.34.4 | Dec 15, 2015 | The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags. | ||
| CVE-2015-7499 | — | < 2.7.6-0.34.4 | 2.7.6-0.34.4 | Dec 15, 2015 | Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors. | ||
| CVE-2015-7498 | — | < 2.7.6-0.34.4 | 2.7.6-0.34.4 | Dec 15, 2015 | Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure. | ||
| CVE-2015-7497 | — | < 2.7.6-0.34.4 | 2.7.6-0.34.4 | Dec 15, 2015 | Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors. | ||
| CVE-2015-5312 | — | < 2.7.6-0.34.4 | 2.7.6-0.34.4 | Dec 15, 2015 | The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660. | ||
| CVE-2015-7942 | — | < 2.7.6-0.34.4 | 2.7.6-0.34.4 | Nov 18, 2015 | The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different | ||
| CVE-2015-7941 | — | < 2.7.6-0.34.4 | 2.7.6-0.34.4 | Nov 18, 2015 | libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as | ||
| CVE-2015-1819 | — | < 2.7.6-0.34.4 | 2.7.6-0.34.4 | Aug 14, 2015 | The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack. |
- affected < 2.7.6-0.37.4fixed 2.7.6-0.37.4
The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed HTML comment.
- CVE-2015-8317Dec 15, 2015affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
- CVE-2015-8242Dec 15, 2015affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
- CVE-2015-8241Dec 15, 2015affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4
The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
- CVE-2015-7500Dec 15, 2015affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4
The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
- CVE-2015-7499Dec 15, 2015affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
- CVE-2015-7498Dec 15, 2015affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
- CVE-2015-7497Dec 15, 2015affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4
Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.
- CVE-2015-5312Dec 15, 2015affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
- CVE-2015-7942Nov 18, 2015affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different
- CVE-2015-7941Nov 18, 2015affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4
libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as
- CVE-2015-1819Aug 14, 2015affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.