Known vulnerabilities in python3-libxml2
Vendor:
OpenAnolis
Software:
python3-libxml2
Software CPE:
cpe:2.3:o:openanolis:python3-libxml2:*:*:*:*:*:anolis_os:*:*
Website:
https://openanolis.cn/
Total vulnerabilities:
37
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (37)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU147357 - Integer overflow CVE-2026-86139 |
CWE-190 | Medium | 2.11.5-21 | 08.09.2026 |
SB2026090826 SB2026092174 |
||
| #VU123115 - Missing release of memory after effective lifetime CVE-2026-1757 |
CWE-401 | Low | 2.11.5-17 | 20.02.2026 |
SB2026022038 SB2026022043 SB2026022044 and 5 more |
||
| #VU122089 - Resource exhaustion CVE-2026-0992 |
CWE-400 | Medium | 2.11.5-17 | 27.01.2026 |
SB2026012787 SB2026012788 SB2026022043 and 7 more |
||
| #VU122088 - Uncontrolled Recursion CVE-2026-0990 |
CWE-674 | Medium | 2.11.5-17 | 27.01.2026 |
SB2026012787 SB2026012788 SB2026022043 and 7 more |
||
| #VU122087 - Uncontrolled Recursion CVE-2026-0989 |
CWE-674 | Medium | 2.11.5-18 | 27.01.2026 |
SB2026012787 SB2026012788 SB2026012963 and 9 more |
||
| #VU115166 - Uncontrolled Recursion CVE-2025-9714 |
CWE-674 | Medium | 2.9.7-21.0.1 | 11.09.2025 |
SB2025091153 SB2025091154 SB2025091275 and 36 more |
||
| #VU113533 - Use After Free CVE-2025-7425 |
CWE-416 | High | 2.9.7-21.0.1, 2.11.5-13 | 31.07.2025 |
SB2025073137 SB2025073144 SB2025073053 and 56 more |
||
| #VU111225 - Integer overflow CVE-2025-6021 |
CWE-190 | High | 2.9.7-21.0.1, 2.11.5-10 | 17.06.2025 |
SB2025061921 SB2025062408 SB2025062747 and 63 more |
||
| #VU111224 - Stack-based buffer overflow CVE-2025-6170 |
CWE-121 | High | 2.9.7-21.0.1, 2.11.5-14 | 17.06.2025 |
SB2025061728 SB2025071874 SB2025071875 and 14 more |
||
| #VU111223 - Type confusion CVE-2025-49796 |
CWE-843 | Medium | 2.9.7-21.0.1 | 17.06.2025 |
SB2025061728 SB2025070832 SB20250709112 and 85 more |
||
| #VU111222 - NULL Pointer Dereference CVE-2025-49795 |
CWE-476 | Medium | 2.11.5-15 | 17.06.2025 |
SB2025070832 SB20250711170 SB20250711171 and 7 more |
||
| #VU111221 - Use After Free CVE-2025-49794 |
CWE-416 | Medium | 2.9.7-21.0.1 | 17.06.2025 |
SB2025061728 SB2025070832 SB20250709112 and 66 more |
||
| #VU107596 - Heap-based Buffer Overflow CVE-2025-32415 |
CWE-122 | High | 2.9.7-21.0.1 | 17.04.2025 |
SB2025041758 SB2025041880 SB2025042531 and 56 more |
||
| #VU107595 - Out-of-bounds read CVE-2025-32414 |
CWE-125 | Medium | 2.11.5-6 | 17.04.2025 |
SB2025041758 SB2025041850 SB2025041880 and 56 more |
||
| #VU104213 - NULL Pointer Dereference CVE-2025-27113 |
CWE-476 | Medium | 2.11.5-9 | 26.02.2025 |
SB2025022619 SB2025022621 SB2025022890 and 32 more |
||
| #VU104099 - Use After Free CVE-2024-56171 |
CWE-416 | High | 2.9.7-19.0.1 | 20.02.2025 |
SB2025022003 SB2025022010 SB2025022023 and 111 more |
||
| #VU104098 - Stack-based buffer overflow CVE-2025-24928 |
CWE-121 | High | 2.9.7-19.0.1, 2.11.5-11 | 20.02.2025 |
SB2025022003 SB2025022010 SB2025022023 and 111 more |
||
| #VU103502 - Use After Free CVE-2022-49043 |
CWE-416 | Medium | 2.9.7-18.0.4 | 03.02.2025 |
SB2025020327 SB2025020330 SB2025020353 and 60 more |
||
| #VU96997 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2024-40896 |
CWE-611 | High | 2.11.5-5 | 10.09.2024 |
SB2024091054 SB2024091056 SB2024091071 and 10 more |
||
| #VU9687 - Memory corruption CVE-2017-9047 |
CWE-119 | Low | 2.9.7-19.0.1, 2.11.5-11 | 19.12.2017 |
SB2017121308 SB2017111019 SB2022110928 and 29 more |
Showing elements 1 - 20 out of 37