cbcvebase.

Libexpat Project Libexpat vulnerabilities

61 known vulnerabilities affecting libexpat_project/libexpat.

Total CVEs
61
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH21MEDIUM28LOW2

Vulnerabilities

Page 1 of 4
CVE-2022-25236P2CRITICALCVSS 9.8fixed in 2.4.52022-02-16
CVE-2022-25236 [CRITICAL] CWE-668 CVE-2022-25236: xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator chara xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
nvd
CVE-2022-25315P3CRITICALCVSS 9.8fixed in 2.4.52022-02-18
CVE-2022-25315 [CRITICAL] CWE-190 CVE-2022-25315: In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
nvd
CVE-2022-22822P3CRITICALCVSS 9.8fixed in 2.4.32022-01-10
CVE-2022-22822 [CRITICAL] CWE-190 CVE-2022-22822: addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2022-23852P3CRITICALCVSS 9.8fixed in 2.4.42022-01-24
CVE-2022-23852 [CRITICAL] CWE-190 CVE-2022-23852: Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
nvd
CVE-2022-22823P3CRITICALCVSS 9.8fixed in 2.4.32022-01-10
CVE-2022-22823 [CRITICAL] CWE-190 CVE-2022-22823: build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2022-22824P3CRITICALCVSS 9.8fixed in 2.4.32022-01-10
CVE-2022-22824 [CRITICAL] CWE-190 CVE-2022-22824: defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2016-0718P3CRITICALCVSS 9.8fixed in 2.2.02016-05-26
CVE-2016-0718 [CRITICAL] CWE-119 CVE-2016-0718: Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute ar Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
nvd
CVE-2022-25235P3CRITICALCVSS 9.8fixed in 2.4.52022-02-16
CVE-2022-25235 [CRITICAL] CWE-116 CVE-2022-25235: xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as che xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
nvd
CVE-2016-4472P3HIGHCVSS 8.1≤ 2.1.12016-06-30
CVE-2016-4472 [HIGH] CVE-2016-4472: The overflow protection in Expat is removed by compilers with certain optimization settings, which a The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
nvd
CVE-2021-45960P3HIGHCVSS 8.8fixed in 2.4.32022-01-01
CVE-2021-45960 [HIGH] CWE-682 CVE-2021-45960: In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
nvd
CVE-2024-45492P3CRITICALCVSS 9.8fixed in 2.6.32024-08-30
CVE-2024-45492 [CRITICAL] CWE-190 CVE-2024-45492: An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
nvd
CVE-2024-45491P3CRITICALCVSS 9.8fixed in 2.6.32024-08-30
CVE-2024-45491 [CRITICAL] CWE-190 CVE-2024-45491: An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
nvd
CVE-2013-0340P3MEDIUMCVSS 6.8fixed in 2.4.02014-01-21
CVE-2013-0340 [MEDIUM] CWE-611 CVE-2013-0340: expat before version 2.4.0 does not properly handle entities expansion unless an application develop expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE
nvd
CVE-2022-22826P3HIGHCVSS 8.8fixed in 2.4.32022-01-10
CVE-2022-22826 [HIGH] CWE-190 CVE-2022-22826: nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2022-22827P3HIGHCVSS 8.8fixed in 2.4.32022-01-10
CVE-2022-22827 [HIGH] CWE-190 CVE-2022-22827: storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2022-22825P3HIGHCVSS 8.8fixed in 2.4.32022-01-10
CVE-2022-22825 [HIGH] CWE-190 CVE-2022-22825: lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
nvd
CVE-2017-9233P3HIGHCVSS 7.5≤ 2.2.02017-07-25
CVE-2017-9233 [HIGH] CWE-611 CVE-2017-9233: XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows at XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
nvd
CVE-2018-20843P3HIGHCVSS 7.5fixed in 2.2.72019-06-24
CVE-2018-20843 [HIGH] CWE-611 CVE-2018-20843: In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colo In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
nvd
CVE-2019-15903P3HIGHCVSS 7.5fixed in 2.2.82019-09-04
CVE-2019-15903 [HIGH] CWE-125 CVE-2019-15903: In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
nvd
CVE-2022-25314P3HIGHCVSS 7.5fixed in 2.4.52022-02-18
CVE-2022-25314 [HIGH] CWE-190 CVE-2022-25314: In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString. In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
nvd
Libexpat Project Libexpat vulnerabilities | cvebase