Search CVE reports


Toggle filters

21 – 30 of 35 results


CVE-2016-1684

Medium priority

Some fixes available 12 of 15

numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource...

3 affected packages

chromium-browser, libxslt, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
libxslt
oxide-qt
Show less packages

CVE-2016-1683

Medium priority

Some fixes available 13 of 15

numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bounds heap memory access) or possibly have...

3 affected packages

chromium-browser, libxslt, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
libxslt
oxide-qt
Show less packages

CVE-2015-9019

Low priority
Ignored

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.

1 affected package

libxslt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxslt Ignored Ignored Ignored
Show less packages

CVE-2015-7995

Low priority

Some fixes available 2 of 4

The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.

1 affected package

libxslt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxslt
Show less packages

CVE-2013-4520

Low priority
Not affected

xslt.c in libxslt before 1.1.25 allows context-dependent attackers to cause a denial of service (crash) via a stylesheet that embeds a DTD, which causes a structure to be accessed as a different type. NOTE: this issue is due to...

1 affected package

libxslt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxslt
Show less packages

CVE-2013-2902

Medium priority

Some fixes available 3 of 4

Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact...

2 affected packages

chromium-browser, libxslt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
libxslt
Show less packages

CVE-2012-6139

Medium priority
Fixed

libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized variable to...

1 affected package

libxslt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxslt
Show less packages

CVE-2012-2893

Medium priority

Some fixes available 9 of 10

Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms.

2 affected packages

libxslt, chromium-browser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxslt
chromium-browser
Show less packages

CVE-2012-2871

Low priority

Some fixes available 9 of 10

libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service...

2 affected packages

chromium-browser, libxslt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
libxslt
Show less packages

CVE-2012-2870

Low priority

Some fixes available 9 of 10

libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is...

2 affected packages

chromium-browser, libxslt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser
libxslt
Show less packages