Vulnerabilities > Xmlsoft > Low

DATE CVE VULNERABILITY TITLE RISK
2018-04-04 CVE-2018-9251 Infinite Loop vulnerability in multiple products
The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.
network
high complexity
xmlsoft debian CWE-835
2.6
2015-11-18 CVE-2015-8035 Resource Management Errors vulnerability in multiple products
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
network
high complexity
debian xmlsoft apple canonical CWE-399
2.6