cbcvebase.
CVE-2012-0876
published 2012-07-03

CVE-2012-0876: The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows…

PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
5.72%
92.2th percentile
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
appleos_x_el_capitan_10.11.2_security_update_2015-005_yosemite_and_security_update_20
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianexpat< expat 2.1.1-3 (bookworm)expat 2.1.1-3 (bookworm)
debianexpat< expat 2.1.0~beta3-1 (bookworm)expat 2.1.0~beta3-1 (bookworm)
debianlibxmltok< expat 2.1.1-3 (bookworm)expat 2.1.1-3 (bookworm)
debianlibxmltok< expat 2.1.0~beta3-1 (bookworm)expat 2.1.0~beta3-1 (bookworm)
debianxmlrpc-c< expat 2.1.0~beta3-1 (bookworm)expat 2.1.0~beta3-1 (bookworm)
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
libexpat_projectlibexpat< 2.2.02.2.0
libexpat_projectlibexpat< 2.1.02.1.0
oraclesolaris

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.