0.35.0
5 years ago
4 months ago
Known vulnerabilities in the libxmljs2 package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
libxmljs2 is a libxml bindings for v8 javascript engine Affected versions of this package are vulnerable to Type Confusion when parsing a specially crafted XML while invoking the namespaces() function (which invokes Exploiting this vulnerability leads to an RCE, data leak DoS on 64-bit and 32-bit systems. How to fix Type Confusion? There is no fixed version for | * |
libxmljs2 is a libxml bindings for v8 javascript engine Affected versions of this package are vulnerable to Type Confusion due to the improper handling of a specially crafted XML file. An attacker can cause a denial of service, data leak, infinite loop, or execute arbitrary code by invoking a function on the result of How to fix Type Confusion? There is no fixed version for | * |