Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 4.5% | — | Canonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+9 | 15/12/2015 | 17/6/2026 | The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660. | |
| Modificada | Baja (2.6) | 3.3% | — | Debian LinuxXmlsoft Libxml2Apple Iphone OSApple MAC OS X+3 | 18/11/2015 | 17/6/2026 | The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data. | |
| Modificada | Media (6.8) | 4.7% | — | HP Icewall Federation AgentHP Icewall File ManagerDebian LinuxApple Iphone OS+5 | 18/11/2015 | 17/6/2026 | The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941. | |
| Modificada | Media (4.3) | 3.1% | — | Canonical Ubuntu LinuxXmlsoft Libxml2 | 18/11/2015 | 17/6/2026 | libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities. | |
| Modificada | Media (5) | 4.0% | — | Xmlsoft Libxml2Apple MAC OS XCanonical Ubuntu LinuxDebian Linux+1 | 4/11/2014 | 17/6/2026 | parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the… | |
| Modificada | Media (6.8) | 3.6% | — | Xmlsoft Libxml2Canonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Server | 21/1/2014 | 16/6/2026 | libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary… | |
| Modificada | Media (5) | 5.0% | — | Google ChromeXmlsoft Libxml2 | 10/7/2013 | 16/6/2026 | parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state. | |
| Modificada | Alta (7.5) | 3.8% | — | Xmlsoft Libxml2 | 25/4/2013 | 16/6/2026 | Multiple use-after-free vulnerabilities in libxml2 2.9.0 and possibly other versions might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to the (1) htmlParseChunk and (2) xmldecl_done functions, as demonstrated by a buffer overflow in the… | |
| Modificada | Media (4.3) | 2.9% | — | Xmlsoft Libxml2Canonical Ubuntu LinuxOpensuse | 25/4/2013 | 16/6/2026 | libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity. | |
| Modificada | Media (5) | 3.3% | — | Xmlsoft Libxml2Apple Iphone OS | 21/12/2012 | 16/6/2026 | libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data. | |
| Modificada | Media (6.8) | 4.4% | — | Google ChromeXmlsoft Libxml2Apple Iphone OS | 28/11/2012 | 16/6/2026 | Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document. | |
| Modificada | Media (6.8) | 2.4% | — | Apple Iphone OSGoogle ChromeXmlsoft Libxml2 | 31/8/2012 | 16/6/2026 | libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document, related to the _xmlNs data… | |
| Modificada | Alta (9.3) | 13% | 💥 Exploit | Xmlsoft Libxml2Xmlsoft Libxml | 2/9/2011 | 16/6/2026 | Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace… | |
| Modificada | Alta (7.5) | 5.9% | — | Google ChromeXmlsoft Libxml2Apple ItunesApple Safari+13 | 7/12/2010 | 16/6/2026 | Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling. | |
| Modificada | Media (4.3) | 2.7% | — | Google ChromeApple ItunesApple SafariApple Iphone OS+11 | 17/11/2010 | 16/6/2026 | libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML… | |
| Modificada | Media (6.5) | 1.8% | — | Xmlsoft LibxmlXmlsoft Libxml2Fedoraproject FedoraDebian Linux+15 | 11/8/2009 | 16/6/2026 | Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing… | |
| Modificada | Media (4.3) | 3.1% | — | Xmlsoft LibxmlXmlsoft Libxml2 | 11/8/2009 | 16/6/2026 | Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML… | |
| Modificada | Media (5) | 8.5% | 💥 Exploit | Xmlsoft Libxml2 | 3/10/2008 | 16/6/2026 | libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and… | |
| Modificada | Alta (10) | 23% | 💥 Exploit | Xmlsoft Libxml2Debian LinuxCanonical Ubuntu LinuxApple Safari+2 | 12/9/2008 | 16/6/2026 | Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name. | |
| Modificada | Media (6.5) | 2.5% | — | Xmlsoft Libxml2Apple SafariApple Iphone OSFedoraproject Fedora+7 | 27/8/2008 | 16/6/2026 | libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document. | |
| Modificada | Alta (10) | 22% | 💥 Exploit | Xmlsoft LibxmlXmlsoft Libxml2Xmlstarlet Command Line XML ToolkitRedhat Fedora Core+2 | 1/3/2005 | 16/6/2026 | Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the… | |
| Modificada | Alta (7.5) | 24% | 💥 Exploit | SGI PropackXmlsoft LibxmlXmlsoft Libxml2 | 15/3/2004 | 16/6/2026 | Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL. | |
| Modificada | Media (6.5) | 1.6% | — | Xmlsoft Libxml2 | 31/12/2003 | 16/6/2026 | libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack." |