rpm package
suse/python-libxml2&distro=SUSE Linux Enterprise Desktop 12
pkg:rpm/suse/python-libxml2&distro=SUSE%20Linux%20Enterprise%20Desktop%2012
Vulnerabilities (29)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2015-7500 | — | < 2.9.1-13.1 | 2.9.1-13.1 | Dec 15, 2015 | The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags. | ||
| CVE-2015-7499 | — | < 2.9.1-13.1 | 2.9.1-13.1 | Dec 15, 2015 | Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors. | ||
| CVE-2015-7498 | — | < 2.9.1-13.1 | 2.9.1-13.1 | Dec 15, 2015 | Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure. | ||
| CVE-2015-7497 | — | < 2.9.1-13.1 | 2.9.1-13.1 | Dec 15, 2015 | Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors. | ||
| CVE-2015-5312 | — | < 2.9.1-13.1 | 2.9.1-13.1 | Dec 15, 2015 | The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660. | ||
| CVE-2015-8035 | — | < 2.9.1-13.1 | 2.9.1-13.1 | Nov 18, 2015 | The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data. | ||
| CVE-2015-7942 | — | < 2.9.1-13.1 | 2.9.1-13.1 | Nov 18, 2015 | The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different | ||
| CVE-2015-7941 | — | < 2.9.1-13.1 | 2.9.1-13.1 | Nov 18, 2015 | libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as | ||
| CVE-2015-1819 | — | < 2.9.1-13.1 | 2.9.1-13.1 | Aug 14, 2015 | The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack. |
- CVE-2015-7500Dec 15, 2015affected < 2.9.1-13.1fixed 2.9.1-13.1
The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
- CVE-2015-7499Dec 15, 2015affected < 2.9.1-13.1fixed 2.9.1-13.1
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
- CVE-2015-7498Dec 15, 2015affected < 2.9.1-13.1fixed 2.9.1-13.1
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
- CVE-2015-7497Dec 15, 2015affected < 2.9.1-13.1fixed 2.9.1-13.1
Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.
- CVE-2015-5312Dec 15, 2015affected < 2.9.1-13.1fixed 2.9.1-13.1
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
- CVE-2015-8035Nov 18, 2015affected < 2.9.1-13.1fixed 2.9.1-13.1
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
- CVE-2015-7942Nov 18, 2015affected < 2.9.1-13.1fixed 2.9.1-13.1
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different
- CVE-2015-7941Nov 18, 2015affected < 2.9.1-13.1fixed 2.9.1-13.1
libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as
- CVE-2015-1819Aug 14, 2015affected < 2.9.1-13.1fixed 2.9.1-13.1
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
Page 2 of 2