cbcvebase.
CVE-2022-40674
published 2022-09-14

CVE-2022-40674: libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

PriorityP342high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.76%
75.5th percentile
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianexpat< expat 2.4.8-2 (bookworm)expat 2.4.8-2 (bookworm)
debianlibxmltok< expat 2.4.8-2 (bookworm)expat 2.4.8-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
libexpat_projectlibexpat< 2.4.92.4.9
mozillafirefox
mozillafirefox>= 0 < 107.0+build2-0ubuntu0.18.04.1107.0+build2-0ubuntu0.18.04.1
mozillafirefox>= 0 < 107.0+build2-0ubuntu0.20.04.1107.0+build2-0ubuntu0.20.04.1
msrcazl3_cmake_3.30.3-6_on_azure_linux_3.0
msrccbl2_expat_2.4.8-2_on_cbl_mariner_2.0
msrccm1_expat_2.4.9-1_on_cbl_mariner_1.0
paloaltopan-os

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.