pkg:Alpine/libxml2

共 36 筆 CVECRITICAL4HIGH19MEDIUM12LOW1

✅ 檢查你的版本

所有已知漏洞

  • CRITICAL9.8CVE-2024-56171libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmls…
    from 0, < 2.11.8-r1
  • CRITICAL9.8CVE-2017-16931libxml2 - security update
    from 0, < 2.9.5-r0
  • CRITICAL9.1CVE-2025-49796A vulnerability was found in libxml2.
    from 0, < 2.13.9-r0
  • CRITICAL9.1CVE-2025-49794A use-after-free vulnerability was found in libxml2.
    from 0, < 2.13.9-r0
  • HIGH8.8CVE-2021-3518Nokogiri Implements libxml2 version vulnerable to use-after-free
    from 0, < 2.9.9-r5
  • HIGH8.8CVE-2016-5131Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a den…
    from 0, < 2.9.4-r1
  • HIGH8.6CVE-2021-3517Nokogiri contains libxml Out-of-bounds Write vulnerability
    from 0, < 2.9.9-r5
  • HIGH7.8CVE-2022-40304An issue was discovered in libxml2 before 2.10.3.
    from 0, < 2.9.14-r2
  • HIGH7.7CVE-2025-24928libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c.
    from 0, < 2.11.8-r1
  • HIGH7.5CVE-2026-6732A flaw was found in libxml2.
    from 0, < 2.13.9-r1
  • HIGH7.5CVE-2025-49795A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions.
    from 0, < 2.13.9-r0
  • HIGH7.5CVE-2025-6021Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
    from 0, < 2.13.9-r0
  • HIGH7.5CVE-2025-32415In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read.
    from 0, < 2.11.8-r3
  • HIGH7.5CVE-2025-32414libxml2 - security update
    from 0, < 2.11.8-r3
  • HIGH7.5CVE-2025-27113libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
    from 0, < 2.11.8-r2
  • HIGH7.5CVE-2024-34459libxml2 - security update
    from 0, < 2.11.8-r0
  • HIGH7.5CVE-2024-25062An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5.
    from 0, < 2.11.7-r0
  • HIGH7.5CVE-2022-40303libxml2 - security update
    from 0, < 2.9.14-r2
  • HIGH7.5CVE-2022-23308valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
    from 0, < 2.9.13-r0
  • HIGH7.5CVE-2020-7595libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation
    from 0, < 2.9.8-r2
  • HIGH7.5CVE-2019-20388xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
    from 0, < 2.9.10-r3
  • HIGH7.5CVE-2019-19956libxml2 - security update
    from 0, < 2.9.9-r3
  • HIGH7.5CVE-2018-14404Nokogiri NULL Pointer Dereference
    from 0, < 2.9.8-r1
  • MEDIUM6.5CVE-2023-29469An issue was discovered in libxml2 before 2.10.4.
    from 0, < 2.10.4-r0
  • MEDIUM6.5CVE-2023-28484libxml2 - security update
    from 0, < 2.10.4-r0
  • MEDIUM6.5CVE-2022-29824libxml2 - security update
    from 0, < 2.9.14-r0
  • MEDIUM6.5CVE-2021-3541libxml2 - security update
    from 0, < 2.9.12-r0
  • MEDIUM6.5CVE-2020-24977GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c.
    from 0, < 2.9.9-r4
  • MEDIUM6.5CVE-2018-14567libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that tri…
    from 0, < 2.9.8-r1
  • MEDIUM6.1CVE-2016-3709libxml2 - security update
    from 0, < 2.9.11-r0
  • MEDIUM5.9CVE-2021-3537Nokogiri Implements libxml2 version vulnerable to null pointer dereferencing
    from 0, < 2.9.9-r5
  • MEDIUM5.5CVE-2016-9318libxml2 - security update
    from 0, < 2.9.4-r2
  • MEDIUM5.3CVE-2022-2309lxml NULL Pointer Dereference allows attackers to cause a denial of service
    from 0, < 2.9.14-r1
  • MEDIUM5.3CVE-2018-9251The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite…
    from 0, < 2.9.8-r1
  • MEDIUM4.7CVE-2017-5969libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML…
    from 0, < 2.9.4-r4
  • LOW2.5CVE-2025-6170A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files.
    from 0, < 2.13.9-r0