📦

libexpat

Vendor: libexpat_project

Actively Exploited 0 CISA KEV List
PoC / Exploits 12 Code Available
Total RCEs 2 Remote Access
Total CVEs 145 Total Indexed
Avg. EPSS 4.30% Exploit Prob.
Latest CVE CVE-2026-56412 Jun 21

Security Vulnerability Index

Page 4 / 15
7.5 CVSS
CVE-2022-43680
Exploit Found

In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

EPSS: 2.26%
8.1 CVSS

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

EPSS: 1.76%
9.8 CVSS
CVE-2022-25315
Exploit Found

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

EPSS: 4.78%
7.5 CVSS
CVE-2022-25314
Exploit Found

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

EPSS: 4.65%
6.5 CVSS

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

EPSS: 3.27%
9.8 CVSS
CVE-2022-25236
Exploit Found

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

EPSS: 35.87%
9.8 CVSS
CVE-2022-25235
Exploit Found

xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.

EPSS: 4.96%
7.5 CVSS
CVE-2022-23990
Exploit Found

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

EPSS: 3.99%
9.8 CVSS
CVE-2022-23852
Exploit Found

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

EPSS: 4.52%
8.8 CVSS
CVE-2022-22827
Exploit Found

storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

EPSS: 2.80%