Libxslt

Vendor:

First CVE: Aug 1, 2008 · Active for 17 years

25
Total CVEs
More Total CVEs than 95% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Libxslt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2008
17 years ago
Most Recent CVE
Jul 10, 2025
379 days ago

CVE Severity & Scoring

Libxslt25 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (8.0%)
Network16 (64.0%)
Unknown7 (28.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (60.0%)
High3 (12.0%)
Unknown7 (28.0%)
User Interaction
None12 (48.0%)
Unknown7 (28.0%)
Required6 (24.0%)
Privileges Required
Low2 (8.0%)
High0 (0.0%)
None16 (64.0%)
Unknown7 (28.0%)

Top CVEs

Signals from CVEs in this product scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Aug 3, 20218.839NONO
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote a
Jul 22, 20169.834NONO
Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in l
Aug 1, 20087.534NOYES
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote a
Jul 22, 20169.833NONO
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead
Apr 10, 20199.832NONO
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote a
Jul 22, 20169.832NONO
The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android,
Apr 24, 20178.829NONO
A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This
Jul 10, 20257.527NONO
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certa
Oct 18, 20197.526NONO
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote a
Jul 22, 20169.826NONO

Exploit Exposure

Signals from CVEs in this product scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (25 CVEs).

Media Mentions

Signals from CVEs in this product scope (25 CVEs).

Top CNAs Publishing CVEs For Libxslt

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.1.945.35.5%01
1.1.845.35.5%01
1.1.724.73.3%00
1.1.624.73.3%00
1.1.524.73.3%00
1.1.424.73.3%00
1.1.3336.05.4%00
1.1.324.73.3%00
1.1.2918.82.1%00
1.1.2615.04.3%00
1.1.2515.04.3%00
1.1.2435.66.5%01
1.1.2345.35.5%01
1.1.2245.35.5%01
1.1.2145.35.5%01
1.1.2045.35.5%01
1.1.224.73.3%00
1.1.1945.35.5%01
1.1.1845.35.5%01
1.1.1745.35.5%01