Vulnerability index

Browse CVEs

27 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libexpat MEDIUM 6.9
CVE-2026-56411

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

Fix: 2.8.2+
Fix from $1,600 2026-06-21
Libexpat MEDIUM 5.9
CVE-2026-56412

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within…

Fix: 2.8.2+
Fix from $1,600 2026-06-21
Libexpat MEDIUM 6.9
CVE-2026-56408

libexpat before 2.8.2 has an integer overflow in copyString.

Fix: 2.8.2+
Fix from $1,600 2026-06-21
Libexpat MEDIUM 6.9
CVE-2026-56410

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

Fix: 2.8.2+
Fix from $1,600 2026-06-21
Libexpat MEDIUM 6.5
CVE-2026-56409

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

Fix: 2.8.2+
Fix from $1,600 2026-06-21
Libexpat MEDIUM 6.9
CVE-2026-56404

libexpat before 2.8.2 has an integer overflow in addBinding.

Fix: 2.8.2+
Fix from $1,600 2026-06-21
Libexpat MEDIUM 6.9
CVE-2026-56405

libexpat before 2.8.2 has an integer overflow in getAttributeId.

Fix: 2.8.2+
Fix from $1,600 2026-06-21
Libexpat MEDIUM 6.9
CVE-2026-56406

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

Fix: 2.8.2+
Fix from $1,600 2026-06-21
Libexpat MEDIUM 6.9
CVE-2026-56407

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

Fix: 2.8.2+
Fix from $1,600 2026-06-21
Libexpat MEDIUM 6.9
CVE-2026-56403

libexpat before 2.8.2 has an integer overflow in storeAtts.

Fix: 2.8.2+
Fix from $1,600 2026-06-21
Libexpat MEDIUM 6.9
CVE-2026-56132

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled w…

Fix: 2.8.2+
Fix from $1,600 2026-06-19
Libexpat MEDIUM 5.9
CVE-2026-50219

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset fr…

Fix: 2.8.2+
Fix from $1,600 2026-06-04
Libexpat HIGH 7.5
CVE-2026-45186

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML…

Fix: 2.8.1+
Fix from $1,950 2026-05-10
Libexpat MEDIUM 5.5
CVE-2026-32776

libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.

Fix: 2.7.5+
Fix from $1,600 2026-03-16
Libexpat MEDIUM 5.5
CVE-2026-32777

libexpat before 2.7.5 allows an infinite loop while parsing DTD content.

Fix: 2.7.5+
Fix from $1,600 2026-03-16
Libexpat MEDIUM 5.5
CVE-2026-32778

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

Fix: 2.7.5+
Fix from $1,600 2026-03-16
Libexpat HIGH 7.8
CVE-2026-25210

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for t…

Fix: 2.7.4+
Fix from $1,950 2026-01-30
Libexpat MEDIUM 5.5
CVE-2025-66382

In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.

Fix: after 2.7.3
Fix from $1,600 2025-11-28
Libexpat HIGH 7.5
CVE-2025-59375

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

Fix: 2.7.2+
Fix from $1,950 2025-09-15
Libexpat CRITICAL 9.8
CVE-2024-45491

An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT…

Fix: 2.6.3+
Fix from $2,300 2024-08-30
Libexpat CRITICAL 9.8
CVE-2024-45492

An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (wh…

Fix: 2.6.3+
Fix from $2,300 2024-08-30
Libexpat HIGH 7.5
CVE-2024-45490

An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

Fix: 2.6.3+
Fix from $1,950 2024-08-30
Libexpat HIGH 7.5
CVE-2023-52425

libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for w…

Fix: after 2.5.0
Fix from $1,950 2024-02-04
Libexpat MEDIUM 5.5
CVE-2023-52426

libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.

Fix: after 2.5.0
Fix from $1,600 2024-02-04
Libexpat HIGH 7.8
CVE-2021-46143

In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.

Fix: 2.4.3 / 3.1+
Fix from $1,950 2022-01-06
Libexpat HIGH 7.8
CVE-2017-11742

The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local users to gain privileges via a …

Patch available
Fix from $1,950 2017-07-30
Libexpat MEDIUM 5.0
CVE-2012-1148

Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (m…

Fix: after 10.11.1
Fix from $1,600 2012-07-03