cbcvebase.

Debian Expat vulnerabilities

45 known vulnerabilities affecting debian/expat.

Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH15MEDIUM11LOW8

Vulnerabilities

Page 3 of 3
CVE-2012-1148P4MEDIUMCVSS 5.0fixed in expat 2.1.0~beta3-1 (bookworm)2012
CVE-2012-1148 [MEDIUM] CVE-2012-1148: expat - Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1... Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities. Scope: local bookworm: resolved (fixed in 2.1.0~beta3-1) bullseye: resolved (fixed in
debian
CVE-2026-32778P4LOWCVSS 2.9fixed in expat 2.7.5-1 (forky)2026
CVE-2026-32778 [LOW] CVE-2026-32778: expat - libexpat before 2.7.5 allows a NULL pointer dereference in the function setConte... libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.7.5-1) sid: resolved (fixed in 2.7.5-1) trixie: open
debian
CVE-2026-32777P4MEDIUMCVSS 4.0fixed in expat 2.7.5-1 (forky)2026
CVE-2026-32777 [MEDIUM] CVE-2026-32777: expat - libexpat before 2.7.5 allows an infinite loop while parsing DTD content. libexpat before 2.7.5 allows an infinite loop while parsing DTD content. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.7.5-1) sid: resolved (fixed in 2.7.5-1) trixie: open
debian
CVE-2026-32776P4MEDIUMCVSS 4.0fixed in expat 2.7.5-1 (forky)2026
CVE-2026-32776 [MEDIUM] CVE-2026-32776: expat - libexpat before 2.7.5 allows a NULL pointer dereference with empty external para... libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.7.5-1) sid: resolved (fixed in 2.7.5-1) trixie: open
debian
CVE-2026-24515P4LOWCVSS 2.9fixed in expat 2.7.3-2 (forky)2026
CVE-2026-24515 [LOW] CVE-2026-24515: expat - In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown e... In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.7.3-2) sid: resolved (fixed in 2.7.3-2) trixie: open
debian
Debian Expat vulnerabilities | cvebase