Libexpat Project

Libexpat

65 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 21.06.2026 15:48:21
  • Zuletzt bearbeitet 23.06.2026 16:29:06

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

  • EPSS 0.13%
  • Veröffentlicht 21.06.2026 15:47:13
  • Zuletzt bearbeitet 23.06.2026 20:14:51

libexpat before 2.8.2 has an integer overflow in getAttributeId.

  • EPSS 0.13%
  • Veröffentlicht 21.06.2026 15:45:55
  • Zuletzt bearbeitet 23.06.2026 20:15:05

libexpat before 2.8.2 has an integer overflow in addBinding.

  • EPSS 0.13%
  • Veröffentlicht 21.06.2026 15:43:55
  • Zuletzt bearbeitet 23.06.2026 20:15:16

libexpat before 2.8.2 has an integer overflow in storeAtts.

  • EPSS 0.11%
  • Veröffentlicht 19.06.2026 03:00:42
  • Zuletzt bearbeitet 23.06.2026 20:15:26

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

  • EPSS 0.14%
  • Veröffentlicht 19.06.2026 02:56:36
  • Zuletzt bearbeitet 23.06.2026 20:15:48

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).

  • EPSS 0.29%
  • Veröffentlicht 04.06.2026 04:20:32
  • Zuletzt bearbeitet 22.07.2026 20:10:00

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,

Exploit
  • EPSS 0.44%
  • Veröffentlicht 10.05.2026 06:36:16
  • Zuletzt bearbeitet 16.09.2026 13:17:58

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

  • EPSS 0.4%
  • Veröffentlicht 16.04.2026 16:52:01
  • Zuletzt bearbeitet 14.07.2026 13:18:51

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

  • EPSS 0.17%
  • Veröffentlicht 16.03.2026 07:02:34
  • Zuletzt bearbeitet 14.07.2026 13:18:49

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.