diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index f7c7b143b9a8..2f914e6c23a1 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,38 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + libxslt -- Denial of Service + + + libxslt + 1.1.29 + + + + +

Google reports:

+
+
    +
  • [583156] Medium CVE-2016-1683: Out-of-bounds access in libxslt. + Credit to Nicolas Gregoire.
  • +
  • [583171] Medium CVE-2016-1684: Integer overflow in libxslt. + Credit to Nicolas Gregoire.
  • +
+
+ +
+ + http://googlechromereleases.blogspot.com/2016/05/stable-channel-update_25.html + CVE-2016-1683 + CVE-2016-1684 + + + 2016-05-25 + 2016-06-20 + +
+ flash -- multiple vulnerabilities @@ -1093,10 +1125,6 @@ Notes: Aleksandar Nikolic of Cisco Talos.
  • [579801] Medium CVE-2016-1682: CSP bypass for ServiceWorker. Credit to KingstonTime.
  • -
  • [583156] Medium CVE-2016-1683: Out-of-bounds access in libxslt. - Credit to Nicolas Gregoire.
  • -
  • [583171] Medium CVE-2016-1684: Integer overflow in libxslt. - Credit to Nicolas Gregoire.
  • [601362] Medium CVE-2016-1685: Out-of-bounds read in PDFium. Credit to Ke Liu of Tencent's Xuanwu LAB.
  • [603518] Medium CVE-2016-1686: Out-of-bounds read in PDFium. @@ -1135,8 +1163,6 @@ Notes: CVE-2016-1680 CVE-2016-1681 CVE-2016-1682 - CVE-2016-1683 - CVE-2016-1684 CVE-2016-1685 CVE-2016-1686 CVE-2016-1687 @@ -1153,6 +1179,7 @@ Notes: 2016-05-25 2016-05-28 + 2016-06-20