CVE-2013-4520: Xmlsoft Libxslt
Medium severity, CVSS 4.3. EPSS: 2.3% chance of exploitation in the next 30 days.
xslt.c in libxslt before 1.1.25 allows context-dependent attackers to cause a denial of service (crash) via a stylesheet that embeds a DTD, which causes a structure to be accessed as a different type. NOTE: this issue is due to an incomplete fix for CVE-2012-2825.
Affected products
- Xmlsoft Libxslt: up to and including 1.1.24; version 0.0.1 only; version 0.1.0 only; version 0.2.0 only; version 0.3.0 only; version 0.4.0 only; …
Published 2013-12-14. Last modified 2026-06-16.