Known vulnerabilities in libxml2 (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:libxml2_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 38
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting libxml2 (Red Hat package) libxml2 (Red Hat package) is affected by 38 known vulnerabilities: 16 high, 17 medium, 5 low Critical High Medium Low

Vulnerabilities (38)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU115166 - Uncontrolled Recursion
CVE-2025-9714
CWE-674 Medium
No
No
2.9.1-6.el7_9.14, 2.9.7-9.el8_4.9, 2.9.7-13.el8_6.13, 2.9.7-16.el8_8.13, 2.9.7-21.el8_10.4, 2.9.13-1.el9_0.8, 2.9.13-3.el9_2.10, 2.9.13-12.el9_6.1, 2.9.13-13.el9_4, 2.9.13-14.el9_7 11.09.2025 SB2025091153
SB2025091154
SB2025091275
and 35 more
#VU113533 - Use After Free
CVE-2025-7425
CWE-416 High
No
No
2.9.1-6.el7_9.12, 2.9.7-9.el8_2.4, 2.9.7-9.el8_4.7, 2.9.7-13.el8_6.11, 2.9.7-16.el8_8.10, 2.9.7-21.el8_10.2, 2.9.13-1.el9_0.6, 2.9.13-3.el9_2.8, 2.9.13-11.el9_6 31.07.2025 SB2025073137
SB2025073144
SB2025073053
and 56 more
#VU111225 - Integer overflow
CVE-2025-6021
CWE-190 High
No
No
2.9.1-6.el7_9.10, 2.9.7-9.el8_2.3, 2.9.7-9.el8_4.6, 2.9.7-13.el8_6.10, 2.9.7-16.el8_8.9, 2.9.7-21.el8_10.1, 2.9.13-1.el9_0.5, 2.9.13-3.el9_2.7, 2.9.13-10.el9_4, 2.9.13-10.el9_6 17.06.2025 SB2025061921
SB2025062408
SB2025062747
and 63 more
#VU111224 - Stack-based buffer overflow
CVE-2025-6170
CWE-121 High
No
No
2.9.7-21.el8_10.6 17.06.2025 SB2025061728
SB2025071874
SB2025071875
and 12 more
#VU111223 - Type confusion
CVE-2025-49796
CWE-843 Medium
No
No
2.9.1-6.el7_9.10, 2.9.7-9.el8_2.3, 2.9.7-9.el8_4.6, 2.9.7-13.el8_6.10, 2.9.7-16.el8_8.9, 2.9.7-21.el8_10.1, 2.9.13-1.el9_0.5, 2.9.13-3.el9_2.7, 2.9.13-10.el9_4, 2.9.13-10.el9_6 17.06.2025 SB2025061728
SB2025070832
SB20250709112
and 84 more
#VU111221 - Use After Free
CVE-2025-49794
CWE-416 Medium
No
No
2.9.1-6.el7_9.10, 2.9.7-9.el8_2.3, 2.9.7-9.el8_4.6, 2.9.7-13.el8_6.10, 2.9.7-16.el8_8.9, 2.9.7-21.el8_10.1, 2.9.13-1.el9_0.5, 2.9.13-3.el9_2.7, 2.9.13-10.el9_4, 2.9.13-10.el9_6 17.06.2025 SB2025061728
SB2025070832
SB20250709112
and 65 more
#VU107596 - Heap-based Buffer Overflow
CVE-2025-32415
CWE-122 High
No
No
2.9.1-6.el7_9.13, 2.9.7-9.el8_2.5, 2.9.7-9.el8_4.8, 2.9.7-13.el8_6.12, 2.9.7-16.el8_8.12, 2.9.7-21.el8_10.3, 2.9.13-1.el9_0.7, 2.9.13-3.el9_2.9, 2.9.13-12.el9_4, 2.9.13-12.el9_6, 2.12.5-9.el10_0 17.04.2025 SB2025041758
SB2025041880
SB2025042531
and 56 more
#VU107595 - Out-of-bounds read
CVE-2025-32414
CWE-125 Medium
No
No
2.9.1-6.el7_9.10, 2.9.7-9.el8_2.3, 2.9.7-9.el8_4.6, 2.9.7-13.el8_6.10, 2.9.7-16.el8_8.9, 2.9.13-1.el9_0.7, 2.9.13-3.el9_2.9, 2.9.13-12.el9_4, 2.9.13-12.el9_6, 2.12.5-9.el10_0 17.04.2025 SB2025041758
SB2025041850
SB2025041880
and 56 more
#VU104099 - Use After Free
CVE-2024-56171
CWE-416 High
No
No
2.9.1-6.el7_9.9, 2.9.7-9.el8_2.1, 2.9.7-9.el8_4.5, 2.9.7-13.el8_6.8, 2.9.7-16.el8_8.7, 2.9.7-19.el8_10, 2.9.13-1.el9_0.4, 2.9.13-3.el9_2.6, 2.9.13-6.el9_5.2, 2.9.13-9.el9_4 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU104098 - Stack-based buffer overflow
CVE-2025-24928
CWE-121 High
No
No
2.9.1-6.el7_9.9, 2.9.7-9.el8_2.1, 2.9.7-9.el8_4.5, 2.9.7-13.el8_6.8, 2.9.7-16.el8_8.7, 2.9.7-19.el8_10, 2.9.13-1.el9_0.4, 2.9.13-3.el9_2.6, 2.9.13-6.el9_5.2, 2.9.13-9.el9_4 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU103502 - Use After Free
CVE-2022-49043
CWE-416 Medium
No
No
2.9.7-16.el8_8.7, 2.9.7-18.el8_10.2, 2.9.13-3.el9_2.4, 2.9.13-6.el9_5.1, 2.9.13-9.el9_4 03.02.2025 SB2025020327
SB2025020330
SB2025020353
and 60 more
#VU89430 - Heap-based Buffer Overflow
CVE-2024-34459
CWE-122 Medium
No
No
2.9.7-9.el8_4.10, 2.9.7-16.el8_8.14, 2.9.7-21.el8_10.5, 2.9.13-3.el9_2.11, 2.9.13-12.el9_6.2, 2.12.5-9.el10_0.1 14.05.2024 SB2024051432
SB2024051433
SB2024051631
and 31 more
#VU86052 - Use After Free
CVE-2024-25062
CWE-416 High
No
No
2.9.7-13.el8_6.5, 2.9.7-16.el8_8.4, 2.9.7-18.el8_10.1, 2.9.13-3.el9_2.3, 2.9.13-6.el9_4 05.02.2024 SB2024020507
SB2024020508
SB2024020742
and 115 more
#VU81044 - Out-of-bounds read
CVE-2023-39615
CWE-125 Medium
No
No
2.9.7-13.el8_6.4, 2.9.7-16.el8_8.2, 2.9.13-5.el9_3 21.09.2023 SB2023092155
SB2023092202
SB2023092203
and 61 more
#VU74863 - NULL Pointer Dereference
CVE-2023-28484
CWE-476 Medium
No
No
2.9.7-13.el8_6.4, 2.9.7-16.el8_8.1, 2.9.13-3.el9_2.1 11.04.2023 SB2023041144
SB2023041145
SB2023041939
and 87 more
#VU74862 - Resource Management Errors
CVE-2023-29469
CWE-399 Medium
No
No
2.9.7-13.el8_6.4, 2.9.7-16.el8_8.1, 2.9.13-3.el9_2.1 11.04.2023 SB2023041144
SB2023041145
SB2023041939
and 84 more
#VU68829 - Resource Management Errors
CVE-2022-40304
CWE-399 Medium
No
No
2.9.7-13.el8_6.4, 2.9.7-15.el8_7.1, 2.9.13-3.el9_1 30.10.2022 SB2022103005
SB2022103006
SB2022103007
and 90 more
#VU68828 - Integer overflow
CVE-2022-40303
CWE-190 High
No
No
2.9.7-13.el8_6.4, 2.9.7-15.el8_7.1, 2.9.13-3.el9_1 30.10.2022 SB2022103005
SB2022103006
SB2022103007
and 88 more
#VU66123 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2016-3709
CWE-79 Medium
No
No
2.9.7-13.el8_6.2, 2.9.7-15.el8 05.08.2022 SB2022080507
SB2022080510
SB2022080808
and 43 more
#VU62741 - Integer overflow
CVE-2022-29824
CWE-190 High
No
No
2.9.13-1.el9_0.1 03.05.2022 SB2022050305
SB2022050306
SB2022050307
and 73 more


Showing elements 1 - 20 out of 38