Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.9
CVE-2026-56411
xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
Libexpat
2.8.2+
MEDIUM 5.9
CVE-2026-56412
libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within…
Libexpat
2.8.2+
MEDIUM 6.9
CVE-2026-56408
libexpat before 2.8.2 has an integer overflow in copyString.
Libexpat
2.8.2+
MEDIUM 6.9
CVE-2026-56410
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
Libexpat
2.8.2+
MEDIUM 6.5
CVE-2026-56409
xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
Libexpat
2.8.2+
MEDIUM 6.9
CVE-2026-56404
libexpat before 2.8.2 has an integer overflow in addBinding.
Libexpat
2.8.2+
MEDIUM 6.9
CVE-2026-56405
libexpat before 2.8.2 has an integer overflow in getAttributeId.
Libexpat
2.8.2+
MEDIUM 6.9
CVE-2026-56406
libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
Libexpat
2.8.2+
MEDIUM 6.9
CVE-2026-56407
libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
Libexpat
2.8.2+
MEDIUM 6.9
CVE-2026-56403
libexpat before 2.8.2 has an integer overflow in storeAtts.
Libexpat
2.8.2+
MEDIUM 6.9
CVE-2026-56132
In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled w…
Libexpat
2.8.2+
MEDIUM 5.9
CVE-2026-50219
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset fr…
Libexpat
2.8.2+
HIGH 7.5
CVE-2026-45186
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML…
Libexpat
2.8.1+
MEDIUM 5.5
CVE-2026-32776
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
Libexpat
2.7.5+
MEDIUM 5.5
CVE-2026-32777
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Libexpat
2.7.5+
MEDIUM 5.5
CVE-2026-32778
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
Libexpat
2.7.5+
HIGH 7.8
CVE-2026-25210
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for t…
Libexpat
2.7.4+
MEDIUM 5.5
CVE-2025-66382
In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
Libexpat
after 2.7.3
HIGH 7.5
CVE-2025-59375
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
Libexpat
2.7.2+
CRITICAL 9.8
CVE-2024-45491
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT…
Libexpat
2.6.3+
CRITICAL 9.8
CVE-2024-45492
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (wh…
Libexpat
2.6.3+
HIGH 7.5
CVE-2024-45490
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
Libexpat
2.6.3+
HIGH 7.5
CVE-2023-52425
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for w…
Libexpat
after 2.5.0
MEDIUM 5.5
CVE-2023-52426
libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.
Libexpat
after 2.5.0
HIGH 7.8
CVE-2021-46143
In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.
Libexpat
2.4.3 / 3.1+
HIGH 7.8
CVE-2017-11742
The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local users to gain privileges via a …
Libexpat
Patch available
MEDIUM 5.0
CVE-2012-1148
Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (m…
Libexpat
after 10.11.1