Platform External Expat vulnerabilities
5 known vulnerabilities affecting platform/external_expat.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1UNKNOWN4
Vulnerabilities
Page 1 of 1
CVE-2022-43680UNKNOWN≥ 10:0, < 10:2023-02-01≥ 11:0, < 11:2023-02-01+3 more2023-02-01
CVE-2022-43680 CVE-2022-43680: In parserCreate of xmlparse
In parserCreate of xmlparse.c, there is a possible use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-25314HIGHCVSS 7.5≥ 10:0, < 10:2022-09-01≥ 11:0, < 11:2022-09-01+2 more2022-09-01
CVE-2022-25314 [HIGH] CVE-2022-25314: (from https://nvd
(from https://nvd.nist.gov/vuln/detail/CVE-2022-25314) In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
In copyString of xmlparse.c, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-23852UNKNOWN≥ 10:0, < 10:2022-09-01≥ 11:0, < 11:2022-09-01+2 more2022-09-01
CVE-2022-23852 CVE-2022-23852: In XML_GetBuffer of xmlparse
In XML_GetBuffer of xmlparse.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-23990UNKNOWN≥ 10:0, < 10:2022-09-01≥ 11:0, < 11:2022-09-01+2 more2022-09-01
CVE-2022-23990 CVE-2022-23990: In closeString of xmlparse
In closeString of xmlparse.c, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-22822UNKNOWN≥ 10:0, < 10:2022-09-01≥ 11:0, < 11:2022-09-01+2 more2022-09-01
CVE-2022-22822 CVE-2022-22822: In storeAtts of xmlparse
In storeAtts of xmlparse.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv