severity: critical clear

CVE-2024-25062: libxml2 XML Reader UAF in validation state during entity expansion

CVE-2024-25062: Use-After-Free in libxml2 XML Reader with DTD Validation and XInclude

criticalruntimecposted 21 hours ago

CVE-2023-29469: NULL dereference in xmlDictComputeFastKey with empty dict strings

CVE-2021-3518 libxml2 use-after-free in xmlXIncludeCopyNode during recursive XInclude

CVE-2022-40304: libxml2 dict corruption via entity reference cycle (content[0]=0 on dict-owned pointer)

CVE-2022-40304 libxml2 dict corruption via entity reference cycles

CVE-2022-40304: Dictionary Corruption via Entity Reference Cycles in libxml2 v2.9.14

CVE-2022-40303: Integer overflow in libxml2 xmlParseCharData → xmlBufAdd with XML_PARSE_HUGE

CVE-2023-0286: OpenSSL X.509 x400Address type confusion — ASN1_STRING decoded, read as ASN1_TYPE

CVE-2023-0286: Type Confusion in OpenSSL X.509 GENERAL_NAME Processing

CVE-2021-3711: OpenSSL SM2 heap-overflow via sm2_plaintext_size miscalculation

CVE-2021-3711: SM2 Plaintext Size Miscalculation Leading to Heap Overflow

criticalposted 21 hours ago

CVE-2022-3602: OpenSSL 3.0 stack buffer overflow in ossl_punycode_decode (off-by-one bounds check)

CVE-2022-3602: OpenSSL Punycode Decoder Stack Buffer Overflow

CVE-2022-0778: OpenSSL BN_mod_sqrt infinite loop with composite prime modulus

CVE-2022-0778 — OpenSSL BN_mod_sqrt infinite loop on non-prime modulus via crafted EC certificate

CVE-2022-0778: Infinite loop in BN_mod_sqrt Tonelli-Shanks algorithm

CVE-2014-0160 Heartbleed: missing bounds check in tls1_process_heartbeat enables OOB heap read

Heartbleed (CVE-2014-0160) - Out-of-bounds Read in OpenSSL TLS Heartbeat

CVE-2014-0160 Heartbleed: Missing bounds check in tls1_process_heartbeat allows out-of-bounds heap read