The Xml Libxml Project maintains libxml, a widely embedded XML parsing library used across countless applications and systems despite its narrow product scope, positioning it as a critical component in the software supply chain. Vulnerabilities in this library warrant attention because a flaw in core parsing logic can propagate across every downstream product that depends on it; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xml Libxml Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-10672CRITICAL Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call. | Jun 29, 2017 | 9.8 | 33 | NO | NO |
CVE-2015-3451MEDIUM The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via cr | May 12, 2015 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xml Libxml Project.
Media articles that mention a CVE ID that affects a product developed by Xml Libxml Project — matched by CVE ID, not by vendor name.