CVEs (62)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data. |
In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time. |
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing. |
3Debian Libexpat ProjectNetapp12Active Iq Unified Manager Debian LinuxH300s Firmware+9 moreJun 17, 2026 Oct 27, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. |
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX). |
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX). |
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer. |
3Fedoraproject Libexpat ProjectNetapp14Active Iq Unified Manager FedoraH300s Firmware+11 moreJun 17, 2026 Mar 10, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate). |
libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time. |
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed. |
4Debian FedoraprojectLibexpat Project+1 more12Active Iq Unified Manager Debian LinuxFedora+9 moreJun 17, 2026 Oct 24, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. |
3Debian FedoraprojectLibexpat Project3Debian Linux FedoraLibexpatJun 17, 2026 Sep 14, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. |
5Debian FedoraprojectLibexpat Project+2 more6Debian Linux FedoraHttp Server+3 moreJun 17, 2026 Feb 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. |
5Debian FedoraprojectLibexpat Project+2 more6Debian Linux FedoraHttp Server+3 moreJun 17, 2026 Feb 18, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString. |
5Debian FedoraprojectLibexpat Project+2 more6Debian Linux FedoraHttp Server+3 moreJun 17, 2026 Feb 18, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element. |
4Debian Libexpat ProjectOracle+1 more5Debian Linux Http ServerLibexpat+2 moreJun 17, 2026 Feb 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs. |
5Debian FedoraprojectLibexpat Project+2 more6Debian Linux FedoraHttp Server+3 moreJun 17, 2026 Feb 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. |
6Debian FedoraprojectLibexpat Project+3 more6Communications Metasolv Solution Debian LinuxFedora+3 moreJun 17, 2026 Jan 26, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. |
6Debian Libexpat ProjectNetapp+3 more7Clustered Data Ontap Communications Metasolv SolutionDebian Linux+4 moreJun 17, 2026 Jan 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES. |
4Debian Libexpat ProjectSiemens+1 more4Debian Linux LibexpatNessus+1 moreJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |