libxml2 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the libxml2 package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • L
Buffer Over-read

*
  • M
Use After Free

*
  • L
Use After Free

*
  • M
Out-of-Bounds

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Double Free

*
  • M
Integer Overflow or Wraparound

*
  • M
Cross-site Scripting (XSS)

*
  • M
Integer Overflow or Wraparound

*
  • M
Use After Free

*
  • M
Unchecked Return Value

<0:2.9.1-6.el7.4
  • M
Resource Exhaustion

<0:2.9.1-6.el7.4
  • M
Memory Leak

<0:2.9.1-6.el7.5
  • H
Uncontrolled Recursion

<0:2.9.1-6.el7_2.3
  • H
Heap-based Buffer Overflow

<0:2.9.1-6.el7_2.3
  • H
Use After Free

<0:2.9.1-6.el7_2.3
  • H
Heap-based Buffer Overflow

<0:2.9.1-6.el7_2.3
  • H
Use After Free

<0:2.9.1-6.el7_2.3
  • H
Heap-based Buffer Overflow

<0:2.9.1-6.el7_2.3
  • H
Heap-based Buffer Overflow

<0:2.9.1-6.el7_2.3
  • H
Use After Free

<0:2.9.1-6.el7_2.3
  • H
Use of Externally-Controlled Format String

<0:2.9.1-6.el7_2.3
  • H
Improper Input Validation

<0:2.9.1-6.el7_2.3
  • H
Heap-based Buffer Overflow

<0:2.9.1-6.el7_2.3
  • H
Uncontrolled Recursion

<0:2.9.1-6.el7_2.3
  • H
Heap-based Buffer Overflow

<0:2.9.1-6.el7_2.3
  • H
Heap-based Buffer Overflow

<0:2.9.1-6.el7_2.3
  • M
Heap-based Buffer Overflow

<0:2.9.1-6.el7_2.2
  • M
Resource Management Errors

<0:2.9.1-6.el7_2.2
  • M
Heap-based Buffer Overflow

<0:2.9.1-6.el7_2.2
  • M
Out-of-bounds Read

<0:2.9.1-6.el7_2.2
  • M
Heap-based Buffer Overflow

<0:2.9.1-6.el7_2.2
  • M
Out-of-Bounds

<0:2.9.1-6.el7_2.2
  • M
Out-of-bounds Read

<0:2.9.1-6.el7_2.2
  • M
Out-of-bounds Read

<0:2.9.1-6.el7_2.2
  • M
Heap-based Buffer Overflow

<0:2.9.1-6.el7_2.2
  • M
Out-of-Bounds

<0:2.9.1-6.el7_2.2
  • M
Heap-based Buffer Overflow

<0:2.9.1-6.el7_2.2
  • M
Resource Management Errors

<0:2.9.1-6.el7_2.2
  • M
XML External Entity (XXE) Injection

<0:2.9.1-5.el7_1.2
  • M
Resource Exhaustion

<0:2.9.1-5.el7_0.1
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:2.9.1-6.el7.5
  • M
Resource Exhaustion

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Use After Free

*
  • M
Use After Free

*
  • M
Improper Input Validation

*
  • M
Missing Release of Resource after Effective Lifetime

<0:2.9.1-6.el7.5
  • M
NULL Pointer Dereference

<0:2.9.1-6.el7.4
  • L
Out-of-bounds Read

*
  • L
NULL Pointer Dereference

*
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • M
XML External Entity (XXE) Injection

*
  • M
Heap-based Buffer Overflow

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • L
Stack-based Buffer Overflow

*
  • M
Heap-based Buffer Overflow

*
  • M
XML External Entity (XXE) Injection

*
  • M
Resource Exhaustion

<0:2.9.1-6.el7.4
  • M
Use After Free

<0:2.9.1-6.el7.4
  • M
Heap-based Buffer Overflow

*
  • M
Use After Free

<0:2.9.1-6.el7.4
  • M
Use After Free

<0:2.9.1-6.el7_9.6