Vulnerabilities
Vulnerable Software
Xmlsoft:  >> Libxml2  >> 2.4.19  Security Vulnerabilities
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
CVSS Score
6.5
EPSS Score
0.008
Published
2008-08-27
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.
CVSS Score
7.5
EPSS Score
0.437
Published
2004-03-15
libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."
CVSS Score
6.5
EPSS Score
0.009
Published
2003-12-31


Contact Us

Shodan ® - All rights reserved