VYPR
Vendor

Libexpat Project

Products
4
CVEs
69
Across products
86
Status
Private

Products

4

Recent CVEs

69
View all 69 CVEs →
  • CVE-2024-45492CriAug 30, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

  • CVE-2024-45491CriAug 30, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

  • CVE-2016-0718CriMay 26, 2016
    risk 0.58cvss 9.8epss 0.13

    Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

  • CVE-2016-9063CriJun 11, 2018
    risk 0.57cvss 9.8epss 0.05

    An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

  • CVE-2016-4472HigJun 30, 2016
    risk 0.54cvss 8.1epss 0.12

    The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix…

  • CVE-2017-11742HigJul 30, 2017
    risk 0.51cvss 7.8epss 0.00

    The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local users to gain privileges via a Trojan horse ADVAPI32.DLL in the current working directory because of an untrusted search path, aka DLL hijacking.

  • CVE-2024-45490HigAug 30, 2024
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

  • CVE-2019-15903HigSep 4, 2019
    risk 0.49cvss 7.5epss 0.07

    In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.

  • CVE-2018-20843HigJun 24, 2019
    risk 0.49cvss 7.5epss 0.07

    In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).

  • CVE-2017-9233HigJul 25, 2017
    risk 0.49cvss 7.5epss 0.09

    XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.

  • CVE-2016-5300HigJun 16, 2016
    risk 0.49cvss 7.5epss 0.07

    The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for…

  • CVE-2026-56411MedJun 21, 2026
    risk 0.45cvss 6.9epss 0.00

    xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

  • CVE-2026-56410MedJun 21, 2026
    risk 0.45cvss 6.9epss 0.00

    xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

  • CVE-2026-56407MedJun 21, 2026
    risk 0.45cvss 6.9epss 0.00

    libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

  • CVE-2026-56406MedJun 21, 2026
    risk 0.45cvss 6.9epss 0.00

    libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

  • CVE-2026-56405MedJun 21, 2026
    risk 0.45cvss 6.9epss 0.00

    libexpat before 2.8.2 has an integer overflow in getAttributeId.

  • CVE-2026-56404MedJun 21, 2026
    risk 0.45cvss 6.9epss 0.00

    libexpat before 2.8.2 has an integer overflow in addBinding.

  • CVE-2026-56403MedJun 21, 2026
    risk 0.45cvss 6.9epss 0.00

    libexpat before 2.8.2 has an integer overflow in storeAtts.

  • CVE-2026-93990HigSep 19, 2026
    risk 0.42cvss 7.5epss 0.00

    Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing…

  • CVE-2026-76641HigAug 20, 2026
    risk 0.42cvss 7.5epss 0.00

    Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to…