CVE-2013-4520: Xmlsoft Libxslt

Medium severity, CVSS 4.3. EPSS: 2.3% chance of exploitation in the next 30 days.

xslt.c in libxslt before 1.1.25 allows context-dependent attackers to cause a denial of service (crash) via a stylesheet that embeds a DTD, which causes a structure to be accessed as a different type. NOTE: this issue is due to an incomplete fix for CVE-2012-2825.

Affected products

  • Xmlsoft Libxslt: up to and including 1.1.24; version 0.0.1 only; version 0.1.0 only; version 0.2.0 only; version 0.3.0 only; version 0.4.0 only; …

Published 2013-12-14. Last modified 2026-06-16.