Количество 16
Количество 16
CVE-2025-9714
Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.
CVE-2025-9714
Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.
CVE-2025-9714
Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.
CVE-2025-9714
Uncontrolled recursion inXPath evaluationin libxml2 up to and includin ...
RLSA-2026:11349
Moderate: libxml2 security update
RLSA-2025:22376
Moderate: libxml2 security update
GHSA-fmj5-rvmp-845r
Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled.
ELSA-2026-22420
ELSA-2026-22420: libxml2 security update (MODERATE)
ELSA-2026-11349
ELSA-2026-11349: libxml2 security update (MODERATE)
ELSA-2025-22376
ELSA-2025-22376: libxml2 security update (MODERATE)
BDU:2026-02937
Уязвимость библиотеки Libxml2, связанная с неконтролируемой рекурсией, позволяющая нарушителю вызвать отказ в обслуживании
SUSE-SU-2025:4115-1
Security update for libxml2
SUSE-SU-2025:4104-1
Security update for libxml2
ROS-20251111-01
Множественные уязвимости libxml2
ALT-PU-2025-13303
ALT-PU-2025-13303: package `libxml2` update to version 2.9.12-alt1.p10.5
ALT-PU-2022-2865
ALT-PU-2022-2865: package `libxml2` update to version 2.10.3-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-9714 Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled. | CVSS3: 6.2 | 0% Низкий | около 1 года назад | |
CVE-2025-9714 Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled. | CVSS3: 6.2 | 0% Низкий | около 1 года назад | |
CVE-2025-9714 Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled. | CVSS3: 6.2 | 0% Низкий | около 1 года назад | |
CVE-2025-9714 Uncontrolled recursion inXPath evaluationin libxml2 up to and includin ... | CVSS3: 6.2 | 0% Низкий | около 1 года назад | |
RLSA-2026:11349 Moderate: libxml2 security update | 0% Низкий | 5 месяцев назад | ||
RLSA-2025:22376 Moderate: libxml2 security update | 0% Низкий | 10 месяцев назад | ||
GHSA-fmj5-rvmp-845r Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth across recursive calls, allowing recursion depth to be controlled. | CVSS3: 6.2 | 0% Низкий | около 1 года назад | |
ELSA-2026-22420 ELSA-2026-22420: libxml2 security update (MODERATE) | 0% Низкий | 3 месяца назад | ||
ELSA-2026-11349 ELSA-2026-11349: libxml2 security update (MODERATE) | 0% Низкий | 5 месяцев назад | ||
ELSA-2025-22376 ELSA-2025-22376: libxml2 security update (MODERATE) | 0% Низкий | 10 месяцев назад | ||
BDU:2026-02937 Уязвимость библиотеки Libxml2, связанная с неконтролируемой рекурсией, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 6.2 | 0% Низкий | около 4 лет назад | |
SUSE-SU-2025:4115-1 Security update for libxml2 | 10 месяцев назад | |||
SUSE-SU-2025:4104-1 Security update for libxml2 | 11 месяцев назад | |||
ROS-20251111-01 Множественные уязвимости libxml2 | CVSS3: 5.5 | 11 месяцев назад | ||
ALT-PU-2025-13303 ALT-PU-2025-13303: package `libxml2` update to version 2.9.12-alt1.p10.5 | CVSS3: 9.8 | 11 месяцев назад | ||
ALT-PU-2022-2865 ALT-PU-2022-2865: package `libxml2` update to version 2.10.3-alt1 | CVSS3: 8.2 | почти 4 года назад |
Уязвимостей на страницу