FlawAtlas
Search the atlas
CVE-2015-8806 High

CVE-2015-8806

dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.

Exploit probability 5.0%
Published April 13, 2016
Required by Not available
Last source change April 16, 2026

02 / AFFECTED SOFTWARE

Affected packages

RubyGems nokogiri

28 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2015-8806

dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.

View original source
Open Source Vulnerabilities GHSA-7hp2-xwpj-95jq

Nokogiri is affected by series of vulnerabilities in libxml2 and libxslt, which are libraries Nokogiri depends on. It was discovered that libxml2 and libxslt incorrectly handled certain malformed documents, which can allow malicious users to cause issues ranging from denial of service to remote code execution attacks.

View original source

05 / REFERENCES

Further evidence