Libexpat Project

Libexpat

65 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 16.03.2026 06:58:06
  • Zuletzt bearbeitet 14.07.2026 13:18:49

libexpat before 2.7.5 allows an infinite loop while parsing DTD content.

  • EPSS 0.16%
  • Veröffentlicht 16.03.2026 06:54:20
  • Zuletzt bearbeitet 14.07.2026 13:18:49

libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.

  • EPSS 0.19%
  • Veröffentlicht 30.01.2026 06:40:27
  • Zuletzt bearbeitet 02.06.2026 14:16:49

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

  • EPSS 0.17%
  • Veröffentlicht 23.01.2026 07:46:36
  • Zuletzt bearbeitet 02.06.2026 14:16:49

In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

  • EPSS 0.21%
  • Veröffentlicht 28.11.2025 00:00:00
  • Zuletzt bearbeitet 02.06.2026 14:16:37

In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.

Medienbericht Exploit
  • EPSS 1.32%
  • Veröffentlicht 15.09.2025 00:00:00
  • Zuletzt bearbeitet 12.05.2026 13:17:22

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

  • EPSS 1.03%
  • Veröffentlicht 27.10.2024 05:15:04
  • Zuletzt bearbeitet 15.10.2025 17:54:22

An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.

  • EPSS 1.39%
  • Veröffentlicht 30.08.2024 03:15:03
  • Zuletzt bearbeitet 12.05.2026 12:17:10

An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

  • EPSS 1.13%
  • Veröffentlicht 30.08.2024 03:15:03
  • Zuletzt bearbeitet 12.05.2026 12:17:10

An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

  • EPSS 1.69%
  • Veröffentlicht 30.08.2024 03:15:03
  • Zuletzt bearbeitet 12.05.2026 12:17:10

An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.