| CVE-2025-6021 | AVG-2899 | High | Yes | Denial of service | The xmlBuildQName function in tree.c is vulnerable to an integer overflow when calculating the required buffer size for concatenating a prefix and a local... | 
					
						| CVE-2022-29824 | AVG-2726 | Medium | Unknown | Arbitrary code execution | Integer overflow in xmlBuf (buf.c) and xmlBuffer (tree.c) can lead to out-of-bounds memory writes exploitable when parsing crafted multi- gigabyte xml files. | 
					
						| CVE-2022-23308 | AVG-2726 | High | Unknown | Arbitrary code execution | Use-after-free of ID and IDREF attributes in valid.c | 
					
						| CVE-2021-3541 | AVG-1883 | Low | Yes | Denial of service | A security issue was found in libxml2 before version 2.9.11. Exponential entity expansion attack its possible bypassing all existing protection mechanisms... | 
					
						| CVE-2021-3537 | AVG-1883 | Low | Yes | Denial of service | It was found that libxml2 before version 2.9.11 did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML... | 
					
						| CVE-2021-3518 | AVG-1883 | Medium | Yes | Arbitrary code execution | A use-after-free security issue was found in libxml2 before version 2.9.11 in xmlXIncludeDoProcess() in xinclude.c when processing crafted files. | 
					
						| CVE-2021-3517 | AVG-1883 | High | Yes | Arbitrary code execution | A heap-based buffer overflow was found in libxml2 before version 2.9.11, as packaged in OpenJFX before version 8u312 in the javafx/web component, when... | 
					
						| CVE-2021-3516 | AVG-1883 | Medium | No | Arbitrary code execution | A use-after-free security issue was found libxml2 before version 2.9.11 when "xmllint --html --push" is used to process crafted files. | 
					
						| CVE-2020-24977 | AVG-1263 | Medium | Yes | Information disclosure | GNOME project libxml2 <= 2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. | 
					
						| CVE-2020-7595 | AVG-1263 | Medium | Yes | Denial of service | xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. | 
					
						| CVE-2019-20388 | AVG-1263 | Medium | Yes | Denial of service | A memory leak was found in the xmlSchemaValidateStream function of libxml2. Applications that use this library may be vulnerable to memory not being freed... | 
					
						| CVE-2018-9251 | AVG-672 | Medium | Yes | Denial of service | A security issue has been found in libxml2 <= 2.9.8 compiled with LZMA support enabled, in the xz_decomp function in xzlib.c. This flaw allows a remote... | 
					
						| CVE-2017-18258 | AVG-671 | Medium | Yes | Denial of service | A security issue has been found in libxml2 <= 2.9.6 compiled with LZMA support enabled, in the xz_head function in xzlib.c. This flaw allows a remote... | 
					
						| CVE-2016-5131 | AVG-56 | Critical | Yes | Arbitrary code execution | Bugs in xmlXPathEvalExpr and xmlXPtrRangeToFunction can lead to a use- after-free and allow control of the instruction pointer. | 
					
						| CVE-2016-4658 | AVG-56 | Critical | Yes | Arbitrary code execution | A use-after-free vulnerability via namespace nodes in XPointer ranges was found in libxml2. |