Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 1.7% | — | Debian LinuxCanonical Ubuntu LinuxXmlsoft Libxml2 | 9/6/2016 | 17/6/2026 | XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors. | |
| Modificada | Crítica (9.8) | 7.0% | — | HP Icewall Federation AgentApple WatchosApple MAC OS XXmlsoft Libxml2+15 | 9/6/2016 | 17/6/2026 | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. | |
| Modificada | Alta (7.5) | 14% | — | HP Icewall Federation AgentCanonical Ubuntu LinuxDebian LinuxOracle VM Server+7 | 9/6/2016 | 17/6/2026 | The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName. | |
| Modificada | Alta (7.8) | 3.2% | — | Debian LinuxApple Iphone OSApple MAC OS XApple Tvos+10 | 20/5/2016 | 17/6/2026 | Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document. | |
| Modificada | Media (5.5) | 7.3% | — | Apple Iphone OSApple MAC OS XApple TvosApple Watchos+10 | 20/5/2016 | 17/6/2026 | The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. | |
| Modificada | Media (5.5) | 6.9% | — | Canonical Ubuntu LinuxDebian LinuxApple Iphone OSApple MAC OS X+10 | 20/5/2016 | 17/6/2026 | The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. | |
| Modificada | Media (5.5) | 4.4% | — | Canonical Ubuntu LinuxDebian LinuxApple Iphone OSApple MAC OS X+10 | 20/5/2016 | 17/6/2026 | Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remote attackers to cause a denial of service via a crafted XML document. | |
| Modificada | Media (5.5) | 4.3% | — | Canonical Ubuntu LinuxDebian LinuxApple Iphone OSApple MAC OS X+10 | 20/5/2016 | 17/6/2026 | Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a crafted XML document. | |
| Modificada | Alta (7.8) | 4.6% | — | Canonical Ubuntu LinuxApple Iphone OSApple MAC OS XApple Tvos+10 | 20/5/2016 | 17/6/2026 | Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document. | |
| Modificada | Media (5.5) | 2.6% | — | Apple Iphone OSApple MAC OS XApple TvosApple Watchos+10 | 20/5/2016 | 17/6/2026 | The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. | |
| Modificada | Alta (7.5) | 5.1% | — | Canonical Ubuntu LinuxXmlsoft Libxml2Debian LinuxHP Icewall Federation Agent+2 | 17/5/2016 | 17/6/2026 | The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of… | |
| Modificada | Alta (7.5) | 7.0% | — | Opensuse LeapDebian LinuxHP Icewall Federation AgentHP Icewall File Manager+10 | 17/5/2016 | 17/6/2026 | The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document. | |
| Modificada | Alta (7.5) | 8.1% | — | PHPXmlsoft Libxml2 | 16/5/2016 | 17/6/2026 | The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before 2.9.2 is used, does not consider the possibility of a NULL valuePop return value before proceeding with a free operation after the principal argument loop, which allows… | |
| Modificada | Alta (7.5) | 7.3% | — | PHPXmlsoft Libxml2 | 16/5/2016 | 17/6/2026 | The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before 2.9.2 is used, does not consider the possibility of a NULL valuePop return value before proceeding with a free operation during initial error checking, which allows… | |
| Modificada | Alta (7.5) | 5.0% | — | Xmlsoft Libxml2Canonical Ubuntu LinuxDebian Linux | 13/4/2016 | 17/6/2026 | dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document. | |
| Modificada | Crítica (9.8) | 4.9% | — | Xmlsoft Libxml2Debian Linux | 11/4/2016 | 17/6/2026 | The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed HTML comment. | |
| Modificada | Alta (8.1) | 6.5% | — | Apple SafariApple Iphone OSApple MAC OS XApple Tvos+11 | 24/3/2016 | 17/6/2026 | The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. | |
| Modificada | Media (6.5) | 2.3% | — | Xmlsoft Libxml2Debian LinuxCanonical Ubuntu Linux | 12/2/2016 | 17/6/2026 | The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document. | |
| Modificada | Media (5) | 5.9% | — | Debian LinuxCanonical Ubuntu LinuxXmlsoft Libxml2Redhat Enterprise Linux Desktop+5 | 15/12/2015 | 17/6/2026 | The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read. | |
| Modificada | Media (5.8) | 4.3% | — | Xmlsoft Libxml2HP Icewall Federation AgentHP Icewall File ManagerApple Iphone OS+8 | 15/12/2015 | 17/6/2026 | The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data. | |
| Modificada | Media (6.4) | 5.4% | — | Debian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+5 | 15/12/2015 | 17/6/2026 | The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data. | |
| Modificada | Media (5) | 5.9% | — | HP Icewall Federation AgentHP Icewall File ManagerXmlsoft Libxml2Debian Linux+9 | 15/12/2015 | 17/6/2026 | The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags. | |
| Modificada | Media (5) | 6.4% | — | Apple Iphone OSApple MAC OS XApple TvosApple Watchos+11 | 15/12/2015 | 17/6/2026 | Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors. | |
| Modificada | Media (5) | 7.2% | — | HP Icewall Federation AgentHP Icewall File ManagerCanonical Ubuntu LinuxDebian Linux+5 | 15/12/2015 | 17/6/2026 | Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure. | |
| Modificada | Media (5) | 7.2% | — | Debian LinuxCanonical Ubuntu LinuxXmlsoft Libxml2Redhat Enterprise Linux Desktop+5 | 15/12/2015 | 17/6/2026 | Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors. |