İçeriğe atla
Noroxi

libexpat project kayıtları

libexpat project üreticisine ait 64 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%98,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

64 kayıt
  • CVE-2022-25236
    50Planlayın

    xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

    KritikCVSS 9,8Kavram kanıtıEPSS %36

    libexpat project · libexpat15 Şub 2022

  • CVE-2016-0718
    43Planlayın

    Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input docum

    KritikCVSS 9,8İstismar yokEPSS %13

    mozilla · firefox26 May 2016

  • CVE-2022-25235
    40Planlayın

    xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is val

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    libexpat project · libexpat15 Şub 2022

  • CVE-2022-22822
    40Planlayın

    addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    libexpat project · libexpat10 Oca 2022

  • CVE-2022-25315
    40Planlayın

    In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    libexpat project · libexpat18 Şub 2022

  • CVE-2022-23852
    40Planlayın

    Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    libexpat project · libexpat23 Oca 2022

  • CVE-2022-22824
    40Planlayın

    defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    KritikCVSS 9,8İstismar yokEPSS %3

    libexpat project · libexpat10 Oca 2022

  • CVE-2022-22823
    40Planlayın

    build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    KritikCVSS 9,8İstismar yokEPSS %3

    libexpat project · libexpat10 Oca 2022

  • CVE-2024-45492
    39İzleyin

    An issue was discovered in libexpat before 2.6.3.

    KritikCVSS 9,8İstismar yokEPSS %1

    libexpat project · libexpat29 Ağu 2024

  • CVE-2024-45491
    39İzleyin

    An issue was discovered in libexpat before 2.6.3.

    KritikCVSS 9,8İstismar yokEPSS %1

    libexpat project · libexpat29 Ağu 2024

  • CVE-2016-4472
    36İzleyin

    The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial

    YüksekCVSS 8,1İstismar yokEPSS %12

    libexpat project · libexpat30 Haz 2016

  • CVE-2021-45960
    36İzleyin

    In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbeh

    YüksekCVSS 8,8Kavram kanıtıEPSS %4

    libexpat project · libexpat1 Oca 2022

  • CVE-2022-22827
    36İzleyin

    storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    YüksekCVSS 8,8İstismar yokEPSS %3

    libexpat project · libexpat10 Oca 2022

  • CVE-2022-22826
    36İzleyin

    nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    YüksekCVSS 8,8İstismar yokEPSS %3

    libexpat project · libexpat10 Oca 2022

  • CVE-2022-22825
    36İzleyin

    lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

    YüksekCVSS 8,8İstismar yokEPSS %3

    libexpat project · libexpat10 Oca 2022

  • CVE-2026-66046
    34İzleyin

    Expat Denial of Service via storeAtts() Quadratic Complexity

    YüksekCVSS 8,7İstismar yokEPSS %1

    libexpat project · libexpat18 Ağu 2026

  • CVE-2013-0340
    33İzleyin

    expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler fun

    OrtaCVSS 6,8İstismar yokEPSS %19

    libexpat project · libexpat21 Oca 2014

  • CVE-2015-1283
    33İzleyin

    Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other prod

    OrtaCVSS 6,8İstismar yokEPSS %18

    google · chrome22 Tem 2015

  • CVE-2017-9233
    33İzleyin

    XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite

    YüksekCVSS 7,5İstismar yokEPSS %9

    libexpat project · libexpat25 Tem 2017

  • CVE-2022-40674
    33İzleyin

    libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

    YüksekCVSS 8,1İstismar yokEPSS %2

    libexpat project · libexpat14 Eyl 2022

  • CVE-2018-20843
    32İzleyin

    In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a h

    YüksekCVSS 7,5İstismar yokEPSS %7

    libexpat project · libexpat24 Haz 2019

  • CVE-2019-15903
    32İzleyin

    In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutiv

    YüksekCVSS 7,5İstismar yokEPSS %7

    libexpat project · libexpat4 Eyl 2019

  • CVE-2016-5300
    32İzleyin

    The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial

    YüksekCVSS 7,5İstismar yokEPSS %7

    canonical · ubuntu linux16 Haz 2016

  • CVE-2021-46143
    32İzleyin

    In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.

    YüksekCVSS 7,8Kavram kanıtıEPSS %4

    libexpat project · libexpat6 Oca 2022

  • CVE-2022-25314
    31İzleyin

    In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

    YüksekCVSS 7,5Kavram kanıtıEPSS %5

    libexpat project · libexpat18 Şub 2022