在 libxml2 2.15.4 之前的版本中,由于 xmlXPtrEval 中 xpointer 长度饱和(length saturation),导致 xmlXPtrEvalXPtrPart 函数存在基于堆的缓冲区溢出漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86140 | 8.0 HIGH | libxml2<2.15.4 valid.c strcat栈溢出 |
| CVE-2026-86139 | 6.9 MEDIUM | libxml2 2.15.4 前 xmlURIEscapeStr 整数溢出 |
| CVE-2026-86138 | 6.9 MEDIUM | libxml2<2.15.4整数溢出致堆缓冲区溢出 |
| CVE-2026-86143 | 6.9 MEDIUM | libxml2 2.15.4 前 xmlIO 整数溢出 |
| CVE-2026-86144 | 5.6 MEDIUM | libxml2 2.15.4前XInclude未传播解析标志致SSRF漏洞 |
| CVE-2026-86141 | 2.9 LOW | libxml2<2.15.4 NULL指针解引用 |
| CVE-2026-86137 | 2.9 LOW | libxml2 <2.15.4 越界读取漏洞 |
No comments yet