libexpat_project CVE 脆弱性と CVE 一覧(61)

製品(CPE): — CVE 件数: 61

libexpat_project 脆弱性概要

libexpat_project 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

一般的な弱点パターンには バッファオーバーフロー、vendor risk memory corruption、vendor risk xxe, and vendor risk cross-site scripting があり、vendor surface software deployment の利用場面で アプリケーションクラッシュ、vendor impact memory corruption, and vendor impact session compromise などのリスクが生じる可能性があります。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 120 / 61 CVE 件数
«« 先頭 « 前へ 1 / 4 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-56412 libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219. [email protected] 4.9 0.10% 2026-06-21 2026-06-23
CVE-2026-56411 xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. [email protected] 6.9 0.11% 2026-06-21 2026-06-23
CVE-2026-56410 xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. [email protected] 6.9 0.11% 2026-06-21 2026-06-23
CVE-2026-56409 xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. [email protected] 6.5 0.10% 2026-06-21 2026-06-23
CVE-2026-56408 libexpat before 2.8.2 has an integer overflow in copyString. [email protected] 6.9 0.10% 2026-06-21 2026-06-23
CVE-2026-56407 libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. [email protected] 6.9 0.10% 2026-06-21 2026-06-23
CVE-2026-56406 libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse. [email protected] 6.9 0.10% 2026-06-21 2026-06-23
CVE-2026-56405 libexpat before 2.8.2 has an integer overflow in getAttributeId. [email protected] 6.9 0.10% 2026-06-21 2026-06-23
CVE-2026-56404 libexpat before 2.8.2 has an integer overflow in addBinding. [email protected] 6.9 0.10% 2026-06-21 2026-06-23
CVE-2026-56403 libexpat before 2.8.2 has an integer overflow in storeAtts. [email protected] 6.9 0.10% 2026-06-21 2026-06-23
CVE-2026-56132 In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers. [email protected] 6.9 0.09% 2026-06-19 2026-06-23
CVE-2026-56131 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation). [email protected] 4.9 0.10% 2026-06-19 2026-06-23
CVE-2026-50219 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, [email protected] 4.9 0.22% 2026-06-04 2026-06-17
CVE-2026-45186 In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. [email protected] 2.9 0.43% 2026-05-10 2026-07-14
CVE-2026-41080 libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. [email protected] 2.9 0.38% 2026-04-16 2026-07-14
CVE-2026-32778 libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition. [email protected] 2.9 0.17% 2026-03-16 2026-07-14
CVE-2026-32777 libexpat before 2.7.5 allows an infinite loop while parsing DTD content. [email protected] 4.0 0.21% 2026-03-16 2026-07-14
CVE-2026-32776 libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content. [email protected] 4.0 0.16% 2026-03-16 2026-07-14
CVE-2026-25210 In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation. [email protected] 6.9 0.19% 2026-01-30 2026-06-17
CVE-2026-24515 In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data. [email protected] 2.9 0.17% 2026-01-23 2026-06-17
«« 先頭 « 前へ 1 / 4 次へ »
cvelogic Threat Intelligence