Libexpat Project
libexpat_project
49 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (49)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianGoogle+1 more4Android Debian LinuxLibexpat+1 moreMay 6, 2026 Jun 16, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the sr...Show more |
9Apple CanonicalDebian+6 more14Debian Linux FirefoxLeap+11 moreMay 6, 2026 May 26, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow. |
8Canonical DebianGoogle+5 more13Chrome Debian LinuxLeap+10 moreMay 6, 2026 Jul 23, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer ove...Show more |
3Apple Libexpat ProjectPython7Ipados Iphone OsLibexpat+4 moreApr 29, 2026 Jan 21, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource cons...Show more |
2Apple Libexpat Project2Libexpat Mac Os XApr 29, 2026 Jul 3, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause i...Show more |
2Apple Libexpat Project2Libexpat Mac Os XApr 29, 2026 Jul 3, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor consumption) via a large number of crafted XML files. |
6Canonical DebianLibexpat Project+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreApr 29, 2026 Jul 3, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU co...Show more |
2Apache Libexpat Project2Http Server LibexpatApr 23, 2026 Dec 4, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with m...Show more |
2Apache Libexpat Project2Http Server LibexpatApr 23, 2026 Nov 3, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) v...Show more |