Vulnerabilities
Vulnerable Software
Xmlsoft:  >> Libxml2  Security Vulnerabilities
xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.
CVSS Score
2.9
EPSS Score
0.001
Published
2026-09-05
In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
CVSS Score
6.9
EPSS Score
0.001
Published
2026-09-05
In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.
CVSS Score
6.9
EPSS Score
0.001
Published
2026-09-05
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).
CVSS Score
5.6
EPSS Score
0.002
Published
2026-09-05
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
CVSS Score
6.9
EPSS Score
0.001
Published
2026-09-05
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
CVSS Score
6.9
EPSS Score
0.001
Published
2026-09-05
In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.
CVSS Score
8.0
EPSS Score
0.001
Published
2026-09-05
In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.
CVSS Score
2.9
EPSS Score
0.001
Published
2026-09-05
libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process. This issue has been fixed in the commit c2e233fc. NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.
CVSS Score
1.8
EPSS Score
0.001
Published
2026-06-29
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
CVSS Score
7.0
EPSS Score
0.004
Published
2026-06-22


Contact Us

Shodan ® - All rights reserved