The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
Conclusion & alert: CVE-2016-4472 is rated Moderate Risk (60.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 2.27%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-04 | 3.51% | 2.27% | -1.23% |
| 2 | 2026-03-01 | 2.33% | 3.51% | +1.17% |
| 3 | 2026-02-21 | — | 2.33% | — |
Full EPSS history (47 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.1 | 3.1 | HIGH |
|
2.2 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2016-4472 not yet assigned priority: Debian including 2 source packages (expat, libxmltok), 7 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5, open 2. | https://security-tracker.debian.org/tracker/CVE-2016-4472 |
gentoo
|
normal | CVE-2016-4472: 1 GLSA(s) (201701-21), 1 atom(s) (dev-libs/expat); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2016-4472 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2016-4472 |
suse
|
medium | CVE-2016-4472 severity moderate: SUSE including 284 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 505 product×package rows across 82 product lines (HPE Helion OpenStack 8, Image SLES12-SP5-Azure-BYOS, … (82 product lines)): Fixed 315, Known Affected 157, Known Not Affected 33. | https://www.suse.com/security/cve/CVE-2016-4472/ |
ubuntu
|
medium | CVE-2016-4472 medium priority: Ubuntu including 26 source packages (audacity, ayttm, …), 615 status rows across 24 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, precise, questing, trusty, upstream, wily, xenial, yakkety, zesty): not-affected 209, DNE 202, ignored 145, needed 29, needs-triage 22, released 8. | https://ubuntu.com/security/CVE-2016-4472 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| libexpat_project | libexpat | <= 2.1.1 | cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 12.04 | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:* |
| mcafee | policy_auditor | < 6.5.1 | cpe:2.3:a:mcafee:policy_auditor:*:*:*:*:*:*:*:* |
| python | python | >= 2.7.0, < 2.7.15 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python | python | >= 3.3.0, < 3.3.7 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python | python | >= 3.4.0, < 3.4.7 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python | python | >= 3.5.0, < 3.5.4 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python | python | >= 3.6.0, < 3.6.2 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/91528 | Third Party Advisory VDB Entry |
| http://www.ubuntu.com/usn/USN-3013-1 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1344251 | Issue Tracking Patch Third Party Advisory |
| https://kc.mcafee.com/corporate/index?page=content&id=SB10365 | Third Party Advisory |
| https://security.gentoo.org/glsa/201701-21 | Third Party Advisory |
| https://sourceforge.net/p/expat/code_git/ci/f0bec73b018caa07d3e75ec8dd967f3785d71bde | Patch Third Party Advisory |
| https://www.tenable.com/security/tns-2016-20 | Third Party Advisory |