Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.1) | 0.28% | — | Xmlsoft LibxsltAI | 14/10/2025 | 1/9/2026 | A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and… | |
| Aplazada | Media (5.5) | 0.17% | — | Xmlsoft LibxsltAI | 25/9/2025 | 2/10/2026 | A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash. | |
| Modificada | Alta (7.5) | 1.2% | — | Xmlsoft LibxsltRedhat Openshift Container PlatformRedhat Enterprise Linux | 10/7/2025 | 1/9/2026 | A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected… | |
| Aplazada | Alta (7.8) | 0.42% | — | Xmlsoft LibxsltAI | 10/7/2025 | 21/9/2026 | A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory,… | |
| Modificada | Alta (7.8) | 0.35% | — | Xmlsoft Libxslt | 14/3/2025 | 17/6/2026 | numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal. | |
| Modificada | Alta (7.8) | 0.35% | — | Xmlsoft Libxslt | 14/3/2025 | 17/6/2026 | xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes. | |
| Modificada | Media (6.5) | 3.8% | — | Xmlsoft Libxml2Xmlsoft LibxsltFedoraproject FedoraDebian Linux+15 | 3/5/2022 | 17/6/2026 | In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for… | |
| Modificada | Alta (8.8) | 18% | — | Google ChromeXmlsoft LibxsltDebian LinuxSplunk Universal Forwarder | 3/8/2021 | 17/6/2026 | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (7.5) | 1.8% | — | Xmlsoft LibxsltDebian Linux | 11/12/2019 | 17/6/2026 | Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data. | |
| Modificada | Alta (7.5) | 4.4% | — | Xmlsoft LibxsltCanonical Ubuntu LinuxDebian Linux | 18/10/2019 | 17/6/2026 | In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed. | |
| Modificada | Media (5.3) | 5.2% | — | Xmlsoft LibxsltOpensuse LeapNetapp Active IQ Unified ManagerNetapp Cloud Backup+21 | 1/7/2019 | 17/6/2026 | In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data. | |
| Modificada | Media (5.3) | 6.5% | — | Xmlsoft LibxsltDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+2 | 1/7/2019 | 17/6/2026 | In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character. | |
| Modificada | Crítica (9.8) | 5.2% | — | Xmlsoft LibxsltCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+18 | 10/4/2019 | 17/6/2026 | libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded. | |
| Modificada | Alta (8.8) | 2.2% | — | Google ChromeXmlsoft LibxsltDebian LinuxRedhat Enterprise Linux Desktop+2 | 24/4/2017 | 17/6/2026 | The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via… | |
| Modificada | Media (5.3) | 2.4% | — | Xmlsoft Libxslt | 5/4/2017 | 17/6/2026 | In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs. | |
| Modificada | Crítica (9.8) | 5.0% | — | Xmlsoft LibxsltApple IcloudApple ItunesFedoraproject Fedora+1 | 22/7/2016 | 17/6/2026 | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different… | |
| Modificada | Crítica (9.8) | 5.0% | — | Xmlsoft LibxsltApple Iphone OSApple MAC OS XApple Tvos+5 | 22/7/2016 | 17/6/2026 | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different… | |
| Modificada | Crítica (9.8) | 4.9% | — | Xmlsoft LibxsltApple IcloudApple ItunesFedoraproject Fedora | 22/7/2016 | 17/6/2026 | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different… | |
| Modificada | Crítica (9.8) | 5.0% | — | Xmlsoft LibxsltApple Iphone OSApple MAC OS XApple Tvos+4 | 22/7/2016 | 17/6/2026 | libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different… | |
| Modificada | Alta (7.5) | 1.8% | — | Google ChromeXmlsoft Libxslt | 5/6/2016 | 17/6/2026 | numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document. | |
| Modificada | Alta (7.5) | 2.1% | — | Xmlsoft LibxsltCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+6 | 5/6/2016 | 17/6/2026 | numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bounds heap memory access) or possibly have unspecified other impact via a crafted document. | |
| Modificada | Media (5) | 4.2% | — | Apple Iphone OSApple MAC OS XApple TvosApple Watchos+1 | 17/11/2015 | 17/6/2026 | The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue. | |
| Modificada | Media (4.3) | 2.3% | — | Xmlsoft Libxslt | 14/12/2013 | 16/6/2026 | xslt.c in libxslt before 1.1.25 allows context-dependent attackers to cause a denial of service (crash) via a stylesheet that embeds a DTD, which causes a structure to be accessed as a different type. NOTE: this issue is due to an incomplete fix for CVE-2012-2825. | |
| Modificada | Media (5) | 4.3% | — | Xmlsoft LibxsltOpensuse | 12/4/2013 | 16/6/2026 | libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized variable to the xsltDocumentFunction function in functions.c. | |
| Modificada | Media (4.3) | 2.5% | — | Apple Iphone OSGoogle ChromeXmlsoft Libxslt | 31/8/2012 | 16/6/2026 | libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the… |