VYPR

rpm package

suse/libxml2-python&distro=SUSE Linux Enterprise Desktop 11 SP4

pkg:rpm/suse/libxml2-python&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4

Vulnerabilities (12)

  • CVE-2015-8710CriApr 11, 2016
    affected < 2.7.6-0.37.4fixed 2.7.6-0.37.4

    The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed HTML comment.

  • CVE-2015-8317Dec 15, 2015
    affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4

    The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

  • CVE-2015-8242Dec 15, 2015
    affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4

    The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.

  • CVE-2015-8241Dec 15, 2015
    affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4

    The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.

  • CVE-2015-7500Dec 15, 2015
    affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4

    The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.

  • CVE-2015-7499Dec 15, 2015
    affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4

    Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.

  • CVE-2015-7498Dec 15, 2015
    affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4

    Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.

  • CVE-2015-7497Dec 15, 2015
    affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4

    Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.

  • CVE-2015-5312Dec 15, 2015
    affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4

    The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.

  • CVE-2015-7942Nov 18, 2015
    affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4

    The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different

  • CVE-2015-7941Nov 18, 2015
    affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4

    libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as

  • CVE-2015-1819Aug 14, 2015
    affected < 2.7.6-0.34.4fixed 2.7.6-0.34.4

    The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.