cbcvebase.
CVE-2016-5300
published 2016-06-16

CVE-2016-5300: The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU…

high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.

Affected

16 ranges
VendorProductVersion rangeFixed in
appleitunes
appleitunes_12.6_for_windows
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianexpat< expat 2.1.1-3 (bookworm)expat 2.1.1-3 (bookworm)
debianlibxmltok< expat 2.1.1-3 (bookworm)expat 2.1.1-3 (bookworm)
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
libexpat_projectlibexpat< 2.2.02.2.0

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM