VYPR

apk package

wolfi/expat

pkg:apk/wolfi/expat

Vulnerabilities (26)

  • CVE-2024-45492CriAug 30, 2024
    affected < 2.6.3-r0fixed 2.6.3-r0

    An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

  • CVE-2024-45491CriAug 30, 2024
    affected < 2.6.3-r0fixed 2.6.3-r0

    An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

  • CVE-2024-45490HigAug 30, 2024
    affected < 2.6.3-r0fixed 2.6.3-r0

    An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

  • CVE-2024-28757HigMar 10, 2024
    affected < 2.6.2-r0fixed 2.6.2-r0

    libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

  • CVE-2022-43680HigOct 24, 2022
    affected < 0fixed 0

    In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

  • CVE-2022-40674HigSep 14, 2022
    affected < 0fixed 0

    libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

Page 2 of 2