Known vulnerabilities in libxml2

Vendor: OpenAnolis
Software: libxml2
Software CPE: cpe:2.3:o:openanolis:libxml2:*:*:*:*:*:anolis_os:*:*
Total vulnerabilities: 37
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting libxml2 libxml2 is affected by 37 known vulnerabilities: 14 high, 20 medium, 3 low Critical High Medium Low

Vulnerabilities (37)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU147357 - Integer overflow
CVE-2026-86139
CWE-190 Medium
No
No
2.11.5-21 08.09.2026 SB2026090826
SB2026092174
#VU123115 - Missing release of memory after effective lifetime
CVE-2026-1757
CWE-401 Low
No
No
2.11.5-17 20.02.2026 SB2026022038
SB2026022043
SB2026022044
and 5 more
#VU122089 - Resource exhaustion
CVE-2026-0992
CWE-400 Medium
No
No
2.11.5-17 27.01.2026 SB2026012787
SB2026012788
SB2026022043
and 7 more
#VU122088 - Uncontrolled Recursion
CVE-2026-0990
CWE-674 Medium
No
No
2.11.5-17 27.01.2026 SB2026012787
SB2026012788
SB2026022043
and 7 more
#VU122087 - Uncontrolled Recursion
CVE-2026-0989
CWE-674 Medium
No
No
2.11.5-18 27.01.2026 SB2026012787
SB2026012788
SB2026012963
and 9 more
#VU115166 - Uncontrolled Recursion
CVE-2025-9714
CWE-674 Medium
No
No
2.9.7-21.0.1 11.09.2025 SB2025091153
SB2025091154
SB2025091275
and 36 more
#VU113533 - Use After Free
CVE-2025-7425
CWE-416 High
No
No
2.9.1-6.0.2, 2.9.7-21.0.1, 2.11.5-13 31.07.2025 SB2025073137
SB2025073144
SB2025073053
and 56 more
#VU111225 - Integer overflow
CVE-2025-6021
CWE-190 High
No
No
2.9.7-21.0.1, 2.11.5-10 17.06.2025 SB2025061921
SB2025062408
SB2025062747
and 63 more
#VU111224 - Stack-based buffer overflow
CVE-2025-6170
CWE-121 High
No
No
2.9.7-21.0.1, 2.11.5-14 17.06.2025 SB2025061728
SB2025071874
SB2025071875
and 14 more
#VU111223 - Type confusion
CVE-2025-49796
CWE-843 Medium
No
No
2.9.7-21.0.1 17.06.2025 SB2025061728
SB2025070832
SB20250709112
and 85 more
#VU111222 - NULL Pointer Dereference
CVE-2025-49795
CWE-476 Medium
No
No
2.11.5-15 17.06.2025 SB2025070832
SB20250711170
SB20250711171
and 7 more
#VU111221 - Use After Free
CVE-2025-49794
CWE-416 Medium
No
No
2.9.7-21.0.1 17.06.2025 SB2025061728
SB2025070832
SB20250709112
and 66 more
#VU107596 - Heap-based Buffer Overflow
CVE-2025-32415
CWE-122 High
No
No
2.9.1-6.0.2, 2.9.7-21.0.1 17.04.2025 SB2025041758
SB2025041880
SB2025042531
and 56 more
#VU107595 - Out-of-bounds read
CVE-2025-32414
CWE-125 Medium
No
No
2.11.5-6 17.04.2025 SB2025041758
SB2025041850
SB2025041880
and 56 more
#VU104213 - NULL Pointer Dereference
CVE-2025-27113
CWE-476 Medium
No
No
2.11.5-9 26.02.2025 SB2025022619
SB2025022621
SB2025022890
and 32 more
#VU104099 - Use After Free
CVE-2024-56171
CWE-416 High
No
No
2.9.1-6.0.2, 2.9.7-19.0.1 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU104098 - Stack-based buffer overflow
CVE-2025-24928
CWE-121 High
No
No
2.9.1-6.0.2, 2.9.7-19.0.1, 2.11.5-11 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU103502 - Use After Free
CVE-2022-49043
CWE-416 Medium
No
No
2.9.7-18.0.4 03.02.2025 SB2025020327
SB2025020330
SB2025020353
and 60 more
#VU96997 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2024-40896
CWE-611 High
No
No
2.11.5-5 10.09.2024 SB2024091054
SB2024091056
SB2024091071
and 10 more
#VU9687 - Memory corruption
CVE-2017-9047
CWE-119 Low
No
No
2.9.1-6.0.2, 2.9.7-19.0.1, 2.11.5-11 19.12.2017 SB2017121308
SB2017111019
SB2022110928
and 29 more


Showing elements 1 - 20 out of 37