Xmlsoft
Xmlsoft Libxslt: vulnerabilidades y CVE
Xmlsoft Libxslt tiene 28 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses1
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-11731 | Baja (3.1) | 0.28% | — | 14 oct 2025 | A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a… |
| CVE-2025-10911 | Media (5.5) | 0.17% | — | 25 sept 2025 | A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash. |
| CVE-2025-7425 | Alta (7.8) | 0.42% | — | 10 jul 2025 | A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this… |
| CVE-2025-7424 | Alta (7.5) | 1.2% | — | 10 jul 2025 | A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to… |
| CVE-2025-24855 | Alta (7.8) | 0.35% | — | 14 mar 2025 | numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue,… |
| CVE-2024-55549 | Alta (7.8) | 0.35% | — | 14 mar 2025 | xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes. |
| CVE-2022-29824 | Media (6.5) | 3.8% | — | 3 may 2022 | In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to… |
| CVE-2021-30560 | Alta (8.8) | 18% | — | 3 ago 2021 | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2019-5815 | Alta (7.5) | 1.8% | — | 11 dic 2019 | Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data. |
| CVE-2019-18197 | Alta (7.5) | 4.4% | — | 18 oct 2019 | In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and… |
| CVE-2019-13118 | Media (5.3) | 5.2% | — | 1 jul 2019 | In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of… |
| CVE-2019-13117 | Media (5.3) | 6.5% | — | 1 jul 2019 | In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains… |
| CVE-2019-11068 | Crítica (9.8) | 5.2% | — | 10 abr 2019 | libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is… |
| CVE-2017-5029 | Alta (8.8) | 2.2% | — | 24 abr 2017 | The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow… |
| CVE-2015-9019 | Media (5.3) | 2.4% | — | 5 abr 2017 | In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs. |
| CVE-2016-4610 | Crítica (9.8) | 5.1% | — | 22 jul 2016 | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service… |
| CVE-2016-4609 | Crítica (9.8) | 5.1% | — | 22 jul 2016 | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service… |
| CVE-2016-4608 | Crítica (9.8) | 5.1% | — | 22 jul 2016 | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service… |
| CVE-2016-4607 | Crítica (9.8) | 5.1% | — | 22 jul 2016 | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service… |
| CVE-2016-1684 | Alta (7.5) | 1.8% | — | 5 jun 2016 | numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or… |
| CVE-2016-1683 | Alta (7.5) | 2.1% | — | 5 jun 2016 | numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bounds heap memory access) or possibly… |
| CVE-2015-7995 | Media (5) | 4.2% | — | 17 nov 2015 | The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion"… |
| CVE-2013-4520 | Media (4.3) | 2.3% | — | 14 dic 2013 | xslt.c in libxslt before 1.1.25 allows context-dependent attackers to cause a denial of service (crash) via a stylesheet that embeds a DTD, which causes a structure to be accessed as a different type. NOTE: this issue… |
| CVE-2012-6139 | Media (5) | 4.3% | — | 12 abr 2013 | libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized… |
| CVE-2012-2870 | Media (4.3) | 2.5% | — | 31 ago 2012 | libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT… |
| CVE-2011-3970 | Media (4.3) | 1.7% | — | 9 feb 2012 | libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. |
| CVE-2011-1202 | Media (4.3) | 2.4% | — | 11 mar 2011 | The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information… |
| CVE-2008-2935 | Alta (7.5) | 13% | — | 1 ago 2008 | Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24… |