Known Vulnerabilities for products from Xmlsoft
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Xmlsoft".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86144 json | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has sec... | Not Provided | 2026-09-05 | 2026-09-15 |
| CVE-2026-86143 json | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach ... | Not Provided | 2026-09-05 | 2026-09-15 |
| CVE-2026-86142 json | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length... | Not Provided | 2026-09-05 | 2026-09-15 |
| CVE-2026-86141 json | xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it doe... | Not Provided | 2026-09-05 | 2026-09-15 |
| CVE-2026-86140 json | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. | Not Provided | 2026-09-05 | 2026-09-15 |
| CVE-2026-86139 json | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. | Not Provided | 2026-09-05 | 2026-09-15 |
| CVE-2026-86138 json | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. | Not Provided | 2026-09-05 | 2026-09-15 |
| CVE-2026-86137 json | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xml... | Not Provided | 2026-09-05 | 2026-09-15 |
| CVE-2026-11979 json | libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The us... | Not Provided | 2026-06-29 | 2026-06-30 |
| CVE-2026-6732 json | A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (... | Not Provided | 2026-04-23 | 2026-08-31 |
| CVE-2026-6653 json | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to ca... | Not Provided | 2026-06-22 | 2026-07-14 |
| CVE-2026-0989 json | A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does... | Not Provided | 2026-01-15 | 2026-09-01 |
| CVE-2025-9714 json | Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a... | Not Provided | 2025-09-10 | 2026-05-12 |
| CVE-2025-8732 json | A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the functi... | Not Provided | 2025-08-08 | 2026-07-01 |
| CVE-2025-7424 json | A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can l... | Not Provided | 2025-07-10 | 2026-09-01 |
| CVE-2025-6170 json | A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an... | Not Provided | 2025-06-16 | 2026-10-01 |
| CVE-2025-6021 json | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack... | Not Provided | 2025-06-12 | 2026-09-18 |
| CVE-2023-45322 json | ** DISPUTED ** libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This ... | 6.5 - MEDIUM | 2023-10-06 | 2023-11-07 |
| CVE-2023-39615 json | ** DISPUTED ** Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function... | 6.5 - MEDIUM | 2023-08-29 | 2023-11-07 |
| CVE-2023-29469 json | An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFa... | 6.5 - MEDIUM | 2023-04-24 | 2023-06-01 |