The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-7500