Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

123 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)4.5%—Canonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+915/12/201517/6/2026
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
ModificadaBaja (2.6)3.3%—Debian LinuxXmlsoft Libxml2Apple Iphone OSApple MAC OS X+318/11/201517/6/2026
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
ModificadaMedia (6.8)4.7%—HP Icewall Federation AgentHP Icewall File ManagerDebian LinuxApple Iphone OS+518/11/201517/6/2026
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.
ModificadaMedia (4.3)3.1%—Canonical Ubuntu LinuxXmlsoft Libxml218/11/201517/6/2026
libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.
ModificadaMedia (5)4.0%—Xmlsoft Libxml2Apple MAC OS XCanonical Ubuntu LinuxDebian Linux+14/11/201417/6/2026
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the…
ModificadaMedia (6.8)3.6%—Xmlsoft Libxml2Canonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Server21/1/201416/6/2026
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary…
ModificadaMedia (5)5.0%—Google ChromeXmlsoft Libxml210/7/201316/6/2026
parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state.
ModificadaAlta (7.5)3.8%—Xmlsoft Libxml225/4/201316/6/2026
Multiple use-after-free vulnerabilities in libxml2 2.9.0 and possibly other versions might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to the (1) htmlParseChunk and (2) xmldecl_done functions, as demonstrated by a buffer overflow in the…
ModificadaMedia (4.3)2.9%—Xmlsoft Libxml2Canonical Ubuntu LinuxOpensuse25/4/201316/6/2026
libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.
ModificadaMedia (5)3.3%—Xmlsoft Libxml2Apple Iphone OS21/12/201216/6/2026
libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.
ModificadaMedia (6.8)4.4%—Google ChromeXmlsoft Libxml2Apple Iphone OS28/11/201216/6/2026
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.
ModificadaMedia (6.8)2.4%—Apple Iphone OSGoogle ChromeXmlsoft Libxml231/8/201216/6/2026
libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document, related to the _xmlNs data…
ModificadaAlta (9.3)13%💥 ExploitXmlsoft Libxml2Xmlsoft Libxml2/9/201116/6/2026
Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace…
ModificadaAlta (7.5)5.9%—Google ChromeXmlsoft Libxml2Apple ItunesApple Safari+137/12/201016/6/2026
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
ModificadaMedia (4.3)2.7%—Google ChromeApple ItunesApple SafariApple Iphone OS+1117/11/201016/6/2026
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML…
ModificadaMedia (6.5)1.8%—Xmlsoft LibxmlXmlsoft Libxml2Fedoraproject FedoraDebian Linux+1511/8/200916/6/2026
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing…
ModificadaMedia (4.3)3.1%—Xmlsoft LibxmlXmlsoft Libxml211/8/200916/6/2026
Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML…
ModificadaMedia (5)8.5%💥 ExploitXmlsoft Libxml23/10/200816/6/2026
libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and…
ModificadaAlta (10)23%💥 ExploitXmlsoft Libxml2Debian LinuxCanonical Ubuntu LinuxApple Safari+212/9/200816/6/2026
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
ModificadaMedia (6.5)2.5%—Xmlsoft Libxml2Apple SafariApple Iphone OSFedoraproject Fedora+727/8/200816/6/2026
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
ModificadaAlta (10)22%💥 ExploitXmlsoft LibxmlXmlsoft Libxml2Xmlstarlet Command Line XML ToolkitRedhat Fedora Core+21/3/200516/6/2026
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the…
ModificadaAlta (7.5)24%💥 ExploitSGI PropackXmlsoft LibxmlXmlsoft Libxml215/3/200416/6/2026
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.
ModificadaMedia (6.5)1.6%—Xmlsoft Libxml231/12/200316/6/2026
libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."