在 libxml2 2.15.4 之前的版本中, 模块存在一个安全漏洞: 与 之间的一致性缺陷,导致负数长度值传递到了 回调函数中。该漏洞的实质是在调用 前缺少对整数溢出的检查。由于该长度值在回调函数内部被广泛使用,因此具有广泛的安全影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86140 | 8.0 HIGH | libxml2<2.15.4 valid.c strcat栈溢出 |
| CVE-2026-86142 | 6.9 MEDIUM | libxml2 2.15.4前 xpointer堆溢出 |
| CVE-2026-86139 | 6.9 MEDIUM | libxml2 2.15.4 前 xmlURIEscapeStr 整数溢出 |
| CVE-2026-86138 | 6.9 MEDIUM | libxml2<2.15.4整数溢出致堆缓冲区溢出 |
| CVE-2026-86144 | 5.6 MEDIUM | libxml2 2.15.4前XInclude未传播解析标志致SSRF漏洞 |
| CVE-2026-86141 | 2.9 LOW | libxml2<2.15.4 NULL指针解引用 |
| CVE-2026-86137 | 2.9 LOW | libxml2 <2.15.4 越界读取漏洞 |
No comments yet