CVE-2026-32777
- EPSS 0.22%
- Veröffentlicht 16.03.2026 06:58:06
- Zuletzt bearbeitet 14.07.2026 13:18:49
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
CVE-2026-32776
- EPSS 0.16%
- Veröffentlicht 16.03.2026 06:54:20
- Zuletzt bearbeitet 14.07.2026 13:18:49
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
CVE-2026-25210
- EPSS 0.19%
- Veröffentlicht 30.01.2026 06:40:27
- Zuletzt bearbeitet 02.06.2026 14:16:49
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
CVE-2026-24515
- EPSS 0.17%
- Veröffentlicht 23.01.2026 07:46:36
- Zuletzt bearbeitet 02.06.2026 14:16:49
In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.
CVE-2025-66382
- EPSS 0.21%
- Veröffentlicht 28.11.2025 00:00:00
- Zuletzt bearbeitet 02.06.2026 14:16:37
In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
CVE-2025-59375
- EPSS 1.32%
- Veröffentlicht 15.09.2025 00:00:00
- Zuletzt bearbeitet 12.05.2026 13:17:22
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
CVE-2024-50602
- EPSS 1.03%
- Veröffentlicht 27.10.2024 05:15:04
- Zuletzt bearbeitet 15.10.2025 17:54:22
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
CVE-2024-45492
- EPSS 1.39%
- Veröffentlicht 30.08.2024 03:15:03
- Zuletzt bearbeitet 12.05.2026 12:17:10
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
CVE-2024-45491
- EPSS 1.13%
- Veröffentlicht 30.08.2024 03:15:03
- Zuletzt bearbeitet 12.05.2026 12:17:10
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
CVE-2024-45490
- EPSS 1.69%
- Veröffentlicht 30.08.2024 03:15:03
- Zuletzt bearbeitet 12.05.2026 12:17:10
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.