libxml2 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the libxml2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
CVE-2025-9714

<2.9.10+dfsg-5ubuntu0.20.04.10+esm2
  • M
Out-of-bounds Write

<2.9.10+dfsg-5ubuntu0.20.04.10+esm1
  • M
Out-of-bounds Read

<2.9.10+dfsg-5ubuntu0.20.04.10+esm1
  • M
Expired Pointer Dereference

<2.9.10+dfsg-5ubuntu0.20.04.10+esm1
  • M
Stack-based Buffer Overflow

<2.9.10+dfsg-5ubuntu0.20.04.10+esm1
  • M
Unchecked Return Value

<2.9.10+dfsg-5ubuntu0.20.04.10
  • M
Out-of-bounds Read

<2.9.10+dfsg-5ubuntu0.20.04.10
  • M
CVE-2024-56171

<2.9.10+dfsg-5ubuntu0.20.04.9
  • M
NULL Pointer Dereference

<2.9.10+dfsg-5ubuntu0.20.04.9
  • M
CVE-2025-24928

<2.9.10+dfsg-5ubuntu0.20.04.9
  • M
CVE-2022-49043

<2.9.10+dfsg-5ubuntu0.20.04.8
  • L
CVE-2024-34459

<2.9.10+dfsg-5ubuntu0.20.04.8
  • M
Use After Free

<2.9.10+dfsg-5ubuntu0.20.04.7
  • M
Double Free

<2.9.10+dfsg-5ubuntu0.20.04.6
  • M
NULL Pointer Dereference

<2.9.10+dfsg-5ubuntu0.20.04.6
  • M
Double Free

<2.9.10+dfsg-5ubuntu0.20.04.5
  • M
Integer Overflow or Wraparound

<2.9.10+dfsg-5ubuntu0.20.04.5
  • M
Cross-site Scripting (XSS)

<2.9.10+dfsg-5ubuntu0.20.04.4
  • L
NULL Pointer Dereference

<2.9.10+dfsg-5ubuntu0.20.04.5
  • M
Integer Overflow or Wraparound

<2.9.10+dfsg-5ubuntu0.20.04.3
  • M
Use After Free

<2.9.10+dfsg-5ubuntu0.20.04.2
  • M
Out-of-bounds Write

<2.9.10+dfsg-5ubuntu0.20.04.1
  • M
Use After Free

<2.9.10+dfsg-5ubuntu0.20.04.1
  • M
Use After Free

<2.9.10+dfsg-5ubuntu0.20.04.1
  • M
NULL Pointer Dereference

<2.9.10+dfsg-5ubuntu0.20.04.1
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<2.9.10+dfsg-5ubuntu0.20.04.1
  • L
Out-of-bounds Read

<2.9.10+dfsg-5ubuntu0.20.04.1
  • L
Missing Release of Resource after Effective Lifetime

<2.9.10+dfsg-1ubuntu2
  • L
Out-of-bounds Read

<2.9.4+dfsg1-6.1ubuntu1