Debian Expat vulnerabilities
45 known vulnerabilities affecting debian/expat.
Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH15MEDIUM11LOW8
Vulnerabilities
Page 3 of 3
CVE-2012-1148P4MEDIUMCVSS 5.0fixed in expat 2.1.0~beta3-1 (bookworm)2012
CVE-2012-1148 [MEDIUM] CVE-2012-1148: expat - Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1...
Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.
Scope: local
bookworm: resolved (fixed in 2.1.0~beta3-1)
bullseye: resolved (fixed in
debian
CVE-2026-32778P4LOWCVSS 2.9fixed in expat 2.7.5-1 (forky)2026
CVE-2026-32778 [LOW] CVE-2026-32778: expat - libexpat before 2.7.5 allows a NULL pointer dereference in the function setConte...
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.7.5-1)
sid: resolved (fixed in 2.7.5-1)
trixie: open
debian
CVE-2026-32777P4MEDIUMCVSS 4.0fixed in expat 2.7.5-1 (forky)2026
CVE-2026-32777 [MEDIUM] CVE-2026-32777: expat - libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.7.5-1)
sid: resolved (fixed in 2.7.5-1)
trixie: open
debian
CVE-2026-32776P4MEDIUMCVSS 4.0fixed in expat 2.7.5-1 (forky)2026
CVE-2026-32776 [MEDIUM] CVE-2026-32776: expat - libexpat before 2.7.5 allows a NULL pointer dereference with empty external para...
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.7.5-1)
sid: resolved (fixed in 2.7.5-1)
trixie: open
debian
CVE-2026-24515P4LOWCVSS 2.9fixed in expat 2.7.3-2 (forky)2026
CVE-2026-24515 [LOW] CVE-2026-24515: expat - In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown e...
In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.7.3-2)
sid: resolved (fixed in 2.7.3-2)
trixie: open
debian
← Previous3 / 3