libexpat project kayıtları
libexpat project üreticisine ait 64 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %98,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-190 Integer Overflow or Wraparound24
- CWE-416 Use After Free6
- CWE-611 Improper Restriction of XML External Entity Reference4
- CWE-476 NULL Pointer Dereference3
- CWE-407 Inefficient Algorithmic Complexity3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
64 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
50Planlayın | CVE-2022-25236Kavram kanıtı | xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.libexpat project · libexpat · CWE-668 | Kritik9,8 | — | %35,9 | 15 Şub 2022 |
43Planlayın | CVE-2016-0718İstismar yok | Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input docummozilla · firefox · CWE-119 | Kritik9,8 | — | %13,3 | 26 May 2016 |
40Planlayın | CVE-2022-25235Kavram kanıtı | xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is vallibexpat project · libexpat · CWE-116 | Kritik9,8 | — | %5,0 | 15 Şub 2022 |
40Planlayın | CVE-2022-22822Kavram kanıtı | addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Kritik9,8 | — | %4,8 | 10 Oca 2022 |
40Planlayın | CVE-2022-25315Kavram kanıtı | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.libexpat project · libexpat · CWE-190 | Kritik9,8 | — | %4,8 | 18 Şub 2022 |
40Planlayın | CVE-2022-23852Kavram kanıtı | Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.libexpat project · libexpat · CWE-190 | Kritik9,8 | — | %4,6 | 23 Oca 2022 |
40Planlayın | CVE-2022-22824İstismar yok | defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Kritik9,8 | — | %3,4 | 10 Oca 2022 |
40Planlayın | CVE-2022-22823İstismar yok | build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Kritik9,8 | — | %3,4 | 10 Oca 2022 |
39İzleyin | CVE-2024-45492İstismar yok | An issue was discovered in libexpat before 2.6.3.libexpat project · libexpat · CWE-190 | Kritik9,8 | — | %1,4 | 29 Ağu 2024 |
39İzleyin | CVE-2024-45491İstismar yok | An issue was discovered in libexpat before 2.6.3.libexpat project · libexpat · CWE-190 | Kritik9,8 | — | %1,1 | 29 Ağu 2024 |
36İzleyin | CVE-2016-4472İstismar yok | The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a deniallibexpat project · libexpat · CWE-119 | Yüksek8,1 | — | %11,9 | 30 Haz 2016 |
36İzleyin | CVE-2021-45960Kavram kanıtı | In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehlibexpat project · libexpat · CWE-682 | Yüksek8,8 | — | %4,2 | 1 Oca 2022 |
36İzleyin | CVE-2022-22827İstismar yok | storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Yüksek8,8 | — | %2,8 | 10 Oca 2022 |
36İzleyin | CVE-2022-22826İstismar yok | nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Yüksek8,8 | — | %2,8 | 10 Oca 2022 |
36İzleyin | CVE-2022-22825İstismar yok | lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.libexpat project · libexpat · CWE-190 | Yüksek8,8 | — | %2,6 | 10 Oca 2022 |
34İzleyin | CVE-2026-66046İstismar yok | Expat Denial of Service via storeAtts() Quadratic Complexitylibexpat project · libexpat · CWE-407 | Yüksek8,7 | — | %0,7 | 18 Ağu 2026 |
33İzleyin | CVE-2013-0340İstismar yok | expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler funlibexpat project · libexpat · CWE-611 | Orta6,8 | — | %19,4 | 21 Oca 2014 |
33İzleyin | CVE-2015-1283İstismar yok | Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other prodgoogle · chrome · CWE-190 | Orta6,8 | — | %18,4 | 22 Tem 2015 |
33İzleyin | CVE-2017-9233İstismar yok | XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinitelibexpat project · libexpat · CWE-611 | Yüksek7,5 | — | %8,7 | 25 Tem 2017 |
33İzleyin | CVE-2022-40674İstismar yok | libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.libexpat project · libexpat · CWE-416 | Yüksek8,1 | — | %2,2 | 14 Eyl 2022 |
32İzleyin | CVE-2018-20843İstismar yok | In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a hlibexpat project · libexpat · CWE-611 | Yüksek7,5 | — | %7,1 | 24 Haz 2019 |
32İzleyin | CVE-2019-15903İstismar yok | In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutivlibexpat project · libexpat · CWE-125 | Yüksek7,5 | — | %6,6 | 4 Eyl 2019 |
32İzleyin | CVE-2016-5300İstismar yok | The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial canonical · ubuntu linux · CWE-399 | Yüksek7,5 | — | %6,5 | 16 Haz 2016 |
32İzleyin | CVE-2021-46143Kavram kanıtı | In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.libexpat project · libexpat · CWE-190 | Yüksek7,8 | — | %3,8 | 6 Oca 2022 |
31İzleyin | CVE-2022-25314Kavram kanıtı | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.libexpat project · libexpat · CWE-190 | Yüksek7,5 | — | %4,7 | 18 Şub 2022 |
- CVE-2022-2523650Planlayın
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
KritikCVSS 9,8Kavram kanıtıEPSS %36libexpat project · libexpat15 Şub 2022
- CVE-2016-071843Planlayın
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input docum
KritikCVSS 9,8İstismar yokEPSS %13mozilla · firefox26 May 2016
- CVE-2022-2523540Planlayın
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is val
KritikCVSS 9,8Kavram kanıtıEPSS %5libexpat project · libexpat15 Şub 2022
- CVE-2022-2282240Planlayın
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
KritikCVSS 9,8Kavram kanıtıEPSS %5libexpat project · libexpat10 Oca 2022
- CVE-2022-2531540Planlayın
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
KritikCVSS 9,8Kavram kanıtıEPSS %5libexpat project · libexpat18 Şub 2022
- CVE-2022-2385240Planlayın
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
KritikCVSS 9,8Kavram kanıtıEPSS %5libexpat project · libexpat23 Oca 2022
- CVE-2022-2282440Planlayın
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
KritikCVSS 9,8İstismar yokEPSS %3libexpat project · libexpat10 Oca 2022
- CVE-2022-2282340Planlayın
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
KritikCVSS 9,8İstismar yokEPSS %3libexpat project · libexpat10 Oca 2022
- CVE-2024-4549239İzleyin
An issue was discovered in libexpat before 2.6.3.
KritikCVSS 9,8İstismar yokEPSS %1libexpat project · libexpat29 Ağu 2024
- CVE-2024-4549139İzleyin
An issue was discovered in libexpat before 2.6.3.
KritikCVSS 9,8İstismar yokEPSS %1libexpat project · libexpat29 Ağu 2024
- CVE-2016-447236İzleyin
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial
YüksekCVSS 8,1İstismar yokEPSS %12libexpat project · libexpat30 Haz 2016
- CVE-2021-4596036İzleyin
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbeh
YüksekCVSS 8,8Kavram kanıtıEPSS %4libexpat project · libexpat1 Oca 2022
- CVE-2022-2282736İzleyin
storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
YüksekCVSS 8,8İstismar yokEPSS %3libexpat project · libexpat10 Oca 2022
- CVE-2022-2282636İzleyin
nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
YüksekCVSS 8,8İstismar yokEPSS %3libexpat project · libexpat10 Oca 2022
- CVE-2022-2282536İzleyin
lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
YüksekCVSS 8,8İstismar yokEPSS %3libexpat project · libexpat10 Oca 2022
- CVE-2026-6604634İzleyin
Expat Denial of Service via storeAtts() Quadratic Complexity
YüksekCVSS 8,7İstismar yokEPSS %1libexpat project · libexpat18 Ağu 2026
- CVE-2013-034033İzleyin
expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler fun
OrtaCVSS 6,8İstismar yokEPSS %19libexpat project · libexpat21 Oca 2014
- CVE-2015-128333İzleyin
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other prod
OrtaCVSS 6,8İstismar yokEPSS %18google · chrome22 Tem 2015
- CVE-2017-923333İzleyin
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite
YüksekCVSS 7,5İstismar yokEPSS %9libexpat project · libexpat25 Tem 2017
- CVE-2022-4067433İzleyin
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
YüksekCVSS 8,1İstismar yokEPSS %2libexpat project · libexpat14 Eyl 2022
- CVE-2018-2084332İzleyin
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a h
YüksekCVSS 7,5İstismar yokEPSS %7libexpat project · libexpat24 Haz 2019
- CVE-2019-1590332İzleyin
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutiv
YüksekCVSS 7,5İstismar yokEPSS %7libexpat project · libexpat4 Eyl 2019
- CVE-2016-530032İzleyin
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial
YüksekCVSS 7,5İstismar yokEPSS %7canonical · ubuntu linux16 Haz 2016
- CVE-2021-4614332İzleyin
In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.
YüksekCVSS 7,8Kavram kanıtıEPSS %4libexpat project · libexpat6 Oca 2022
- CVE-2022-2531431İzleyin
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
YüksekCVSS 7,5Kavram kanıtıEPSS %5libexpat project · libexpat18 Şub 2022