CVE-2022-40674
published 2022-09-14CVE-2022-40674: libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
PriorityP342high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.76%
75.5th percentile
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | expat | < expat 2.4.8-2 (bookworm) | expat 2.4.8-2 (bookworm) |
| debian | libxmltok | < expat 2.4.8-2 (bookworm) | expat 2.4.8-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libexpat_project | libexpat | < 2.4.9 | 2.4.9 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 107.0+build2-0ubuntu0.18.04.1 | 107.0+build2-0ubuntu0.18.04.1 |
| mozilla | firefox | >= 0 < 107.0+build2-0ubuntu0.20.04.1 | 107.0+build2-0ubuntu0.20.04.1 |
| msrc | azl3_cmake_3.30.3-6_on_azure_linux_3.0 | — | — |
| msrc | cbl2_expat_2.4.8-2_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_expat_2.4.9-1_on_cbl_mariner_1.0 | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
firefox vulnerabilities
osv·2022-11-16·CVSS 8.1
CVE-2022-45403 [HIGH] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were tricked
into opening a specially crafted website, an attacker could potentially
exploit these to cause a denial of service, spoof the contents of the
addressbar, bypass security restrictions, cross-site tracing or execute
arbitrary code. (CVE-2022-45403, CVE-2022-45404, CVE-2022-45405,
CVE-2022-45406, CVE-2022-45407, CVE-2022-45408, CVE-2022-45409, CVE-2022-45410,
CVE-2022-45411, CVE-2022-45413, CVE-2022-40674, CVE-2022-45418, CVE-2022-45419,
CVE-2022-45420, CVE-2022-45421)
Armin Ebert discovered that Firefox did not properly manage while resolving
file symlink. If a user were tricked into opening a specially crafted weblink,
an attacker could potentially exploit these to cause a denial of service
GHSA
GHSA-2vq2-xc55-3j5m: libexpat before 2
ghsa_unreviewed·2022-09-15
CVE-2022-40674 [CRITICAL] CWE-416 GHSA-2vq2-xc55-3j5m: libexpat before 2
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
OSV
CVE-2022-40674: libexpat before 2
osv·2022-09-14·CVSS 8.1
CVE-2022-40674 [HIGH] CVE-2022-40674: libexpat before 2
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
CISA ICS
ABB M2M Gateway
cisa_ics·2025-04-15
ABB M2M Gateway
ICS Advisory
##
ABB M2M Gateway
Release DateApril 15, 2025
Alert CodeICSA-25-105-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: M2M Gateway
- Vulnerabilities: Integer Overflow or Wraparound, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Unquoted Search Path or Element, Untrusted Search Path, Use After Free, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Missing Release of Memory after Effective Lifetime, Allocation of Resources Without Limits or Throttling, Improper Privilege Management, Improper Limitati
Palo Alto
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-10-29·CVSS 9.8
CVE-2019-17006 [CRITICAL] PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2019-17006 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-3518 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-25219 This CVE is fixed in PAN-OS 10.2.3, and all later versions of PAN-OS. CVE-2021-27645 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions of PAN-OS. CVE-2021-34798 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions o
CISA ICS
Hitachi Energy’s AFS65x, AFS67x, AFR67x and AFF66x Products
cisa_ics·2023-05-23·CVSS 8.1
[HIGH] Hitachi Energy’s AFS65x, AFS67x, AFR67x and AFF66x Products
ICS Advisory
##
Hitachi Energy’s AFS65x, AFS67x, AFR67x and AFF66x Products
Release DateMay 23, 2023
Alert CodeICSA-23-143-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: AFS65x, AFS67x, AFR67x and AFF66x series products
- Vulnerabilities: Use After Free
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information or lead to a Denial-of-Service (DoS).
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Hitachi Energy’s AFS65x, AFS67x, AFR67x and AFF66x series products, are affected:
- AFS660/665S, AFS660/665C, AFS670v2: Firmware 7.1.05 and earlier
- AFS670/675, AFR67x: Firmware
CISA ICS
Siemens SINEC NMS Third-Party
cisa_ics·2023-05-11·CVSS 9.8
[CRITICAL] Siemens SINEC NMS Third-Party
ICS Advisory
##
Siemens SINEC NMS Third-Party
Release DateMay 11, 2023
Alert CodeICSA-23-131-05
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Third-party components libexpat and libcurl in SINEC NMS
- Vulnerabilities: Expected Behavior Violation, Improper Validation of Syntactic Correctness of Input, Stack-based Buffer Overflow, Use After Free, Double Free, Cleartext Tran
CISA ICS
Siemens SCALANCE XCM332
cisa_ics·2023-04-13·CVSS 7.5
[HIGH] Siemens SCALANCE XCM332
ICS Advisory
##
Siemens SCALANCE XCM332
Release DateApril 13, 2023
Alert CodeICSA-23-103-09
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM332
- Vulnerabilities: Allocation of Resources Without Limits or Throttling, Use After Free, Concurrent Execution Using Shared Resource with Improper Synchronization ('Race Condition'), Incorrect Default Permissions, Out-of-
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2023-02-28
CVE-2022-40674 Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Expat could be made to crash or execute arbitrary code.
USN-5638-1 fixed several vulnerabilities in Expat. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Rhodri James discovered that Expat incorrectly handled memory when
processing certain malformed XML files. An attacker could possibly
use this issue to cause a crash or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2022-11-17·CVSS 7.5
CVE-2022-43680 [HIGH] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Expat could be made to crash or execute arbitrary code.
USN-5638-1 fixed a vulnerability in Expat. This update provides
the corresponding updates for Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS.
It was discovered that Expat incorrectly handled memory in out-of-memory
situations. An attacker could possibly use this issue to cause a crash,
resulting in a denial of service, or possibly execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS. (CVE-2022-43680)
Original advisory details:
Rhodri James discovered that Expat incorrectly handled memory when
processing certain malformed XML files. An attacker could possibly
use this issue to cause a crash or execute arbitrary code.
Instructions: In general, a standard system update wil
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2022-11-16·CVSS 8.1
CVE-2022-40674 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were tricked
into opening a specially crafted website, an attacker could potentially
exploit these to cause a denial of service, spoof the contents of the
addressbar, bypass security restrictions, cross-site tracing or execute
arbitrary code. (CVE-2022-45403, CVE-2022-45404, CVE-2022-45405,
CVE-2022-45406, CVE-2022-45407, CVE-2022-45408, CVE-2022-45409, CVE-2022-45410,
CVE-2022-45411, CVE-2022-45413, CVE-2022-40674, CVE-2022-45418, CVE-2022-45419,
CVE-2022-45420, CVE-2022-45421)
Armin Ebert discovered that Firefox did not properly manage while resolving
file symlink. If a user were tricked into opening a specially crafted weblink,
an attac
Ubuntu
Expat vulnerability
vendor_ubuntu·2022-09-26
CVE-2022-40674 Expat vulnerability
Title: Expat vulnerability
Summary: Expat could be made to crash or execute arbitrary code.
Rhodri James discovered that Expat incorrectly handled memory when
processing certain malformed XML files. An attacker could possibly
use this issue to cause a crash or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
BSD
OpenBSD 7.1 Errata 010: SECURITY FIX
bsd_advisories·2022-09-23·CVSS 8.1
CVE-2022-40674 [HIGH] OpenBSD 7.1 Errata 010: SECURITY FIX
OpenBSD 7.1 Errata 010: SECURITY FIX
010: SECURITY FIX: September 23, 2022
All architectures In libexpat fix heap use-after-free vulnerability CVE-2022-40674.
BSD
OpenBSD 7.0 Errata 025: SECURITY FIX
bsd_advisories·2022-09-23·CVSS 8.1
CVE-2022-40674 [HIGH] OpenBSD 7.0 Errata 025: SECURITY FIX
OpenBSD 7.0 Errata 025: SECURITY FIX
025: SECURITY FIX: September 23, 2022
All architectures In libexpat fix heap use-after-free vulnerability CVE-2022-40674.
Red Hat
expat: a use-after-free in the doContent function in xmlparse.c
vendor_redhat·2022-09-14·CVSS 8.1
CVE-2022-40674 [HIGH] CWE-416 expat: a use-after-free in the doContent function in xmlparse.c
expat: a use-after-free in the doContent function in xmlparse.c
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
A vulnerability was found in expat. With this flaw, it is possible to create a situation in which parsing is suspended while substituting in an internal entity so that XML_ResumeParser directly uses the internalEntityProcessor as its processor. If the subsequent parse includes some unclosed tags, this will return without calling storeRawNames to ensure that the raw versions of the tag names are stored in memory other than the parse buffer itself. Issues occur if the parse buffer is changed or reallocated (for example, if processing a file line by line), problems occur. Using this vulnerability in the doContent function allows an attacker to t
Microsoft
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
vendor_msrc·2022-09-13·CVSS 8.1
CVE-2022-40674 [HIGH] CWE-416 libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Mariner Releas
Debian
CVE-2022-40674: expat - libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse...
vendor_debian·2022·CVSS 8.1
CVE-2022-40674 [HIGH] CVE-2022-40674: expat - libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse...
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
Scope: local
bookworm: resolved (fixed in 2.4.8-2)
bullseye: resolved (fixed in 2.2.10-2+deb11u4)
forky: resolved (fixed in 2.4.8-2)
sid: resolved (fixed in 2.4.8-2)
trixie: resolved (fixed in 2.4.8-2)
Mozilla
Mozilla Foundation Security Advisory 2022-47: CVE-2022-40674
vendor_mozilla·CVSS 8.1
CVE-2022-40674 [HIGH] Mozilla Foundation Security Advisory 2022-47: CVE-2022-40674
Mozilla Foundation Security Advisory 2022-47
CVE: CVE-2022-40674
Product: Firefox
Impact: high
Fixed in: Firefox 107
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-40674 expat: a use-after-free in the doContent function in xmlparse.c
bugzilla·2022-09-29·CVSS 8.1
CVE-2022-40674 [HIGH] CVE-2022-40674 expat: a use-after-free in the doContent function in xmlparse.c
CVE-2022-40674 expat: a use-after-free in the doContent function in xmlparse.c
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
https://github.com/advisories/GHSA-2vq2-xc55-3j5m
https://github.com/libexpat/libexpat/pull/629
https://github.com/libexpat/libexpat/pull/640
https://www.debian.org/security/2022/dsa-5236
https://lists.debian.org/debian-lts-announce/2022/09/msg00029.html
Discussion:
Created expat tracking bugs for this issue:
Affects: fedora-35 [bug 2130777]
Affects: fedora-36 [bug 2130780]
Created mingw-expat tracking bugs for this issue:
Affects: fedora-35 [bug 2130778]
Affects: fedora-36 [bug 2130781]
Created xmlrpc-c tracking bugs for this issue:
Affects: fedora-35 [bug 2130779]
Affects: fedora-36 [bug 2130782]
---
This issue has
Bugzilla
Evaluate expat CVE-2022-40674 fix
bugzilla·2022-09-20·CVSS 8.1
CVE-2022-40674 [HIGH] Evaluate expat CVE-2022-40674 fix
Evaluate expat CVE-2022-40674 fix
The new expat 2.4.9 release shipped today included a CVE fix:
> #629 #640 CVE-2022-40674 -- Heap use-after-free vulnerability in function doContent. Expected impact is denial of service or potentially arbitrary code execution.
https://github.com/libexpat/libexpat/pull/629/commits/4a32da87e931ba54393d465bb77c40b5c33d343b
While our RLBox sandboxing likely mitigates the severity of this issue, we still might want to consider cherry-picking the fix to our import for safety's sake.
Discussion:
*** Bug 1792783 has been marked as a duplicate of this bug. ***
---
[Tracking Requested - why for this release]: From a background conversation with Tom -- RLBoxing makes this less severe, but we should get this fixed and uplifted
---
The 2.4.9-based patch linked
https://github.com/libexpat/libexpat/pull/629https://github.com/libexpat/libexpat/pull/640https://lists.debian.org/debian-lts-announce/2022/09/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GSVZN3IJ6OCPSJL7AEX3ZHSHAHFOGESK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J2IGJNHFV53PYST7VQV3T4NHVYAMXA36/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LQB6FJAM5YQ35SF5B2MN25Y2FX56EOEZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2ZKEPGFCZ7R6DRVH3K6RBJPT42ZBEG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XCGBVQQ47URGJAZWHCISHDWF6QBTV2LE/https://security.gentoo.org/glsa/202209-24https://security.gentoo.org/glsa/202211-06https://security.netapp.com/advisory/ntap-20221028-0008/https://www.debian.org/security/2022/dsa-5236https://github.com/libexpat/libexpat/pull/629https://github.com/libexpat/libexpat/pull/640https://lists.debian.org/debian-lts-announce/2022/09/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GSVZN3IJ6OCPSJL7AEX3ZHSHAHFOGESK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J2IGJNHFV53PYST7VQV3T4NHVYAMXA36/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LQB6FJAM5YQ35SF5B2MN25Y2FX56EOEZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2ZKEPGFCZ7R6DRVH3K6RBJPT42ZBEG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XCGBVQQ47URGJAZWHCISHDWF6QBTV2LE/https://security.gentoo.org/glsa/202209-24https://security.gentoo.org/glsa/202211-06https://security.netapp.com/advisory/ntap-20221028-0008/https://www.debian.org/security/2022/dsa-5236
2022-09-14
Published