Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.

Expat_jll

JLSEC-2026-384Low 2.9UpstreamNo summary availableJLSEC-2026-383Medium 5.5UpstreamNo summary availableJLSEC-2026-382Medium 5.5UpstreamNo summary availableJLSEC-2026-381Medium 5.5UpstreamNo summary availableJLSEC-2026-380High 7.8UpstreamNo summary availableJLSEC-2026-379Low 2.5UpstreamNo summary availableJLSEC-2026-378Medium 5.5UpstreamNo summary availableJLSEC-2025-173High 7.5Upstreamlibexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocatio…JLSEC-2025-65Medium 5.9UpstreamAn issue was discovered in libexpat before 2.6.4JLSEC-2025-64Critical 9.8UpstreamAn issue was discovered in libexpat before 2.6.3JLSEC-2025-63Critical 9.8UpstreamAn issue was discovered in libexpat before 2.6.3JLSEC-2025-62High 7.5UpstreamAn issue was discovered in libexpat before 2.6.3JLSEC-2025-61High 7.5Upstreamlibexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use o…JLSEC-2025-59Medium 5.5Upstreamlibexpat through 2.5.0 allows recursive XML Entity Expansion if `XML_DTD` is undefined at…JLSEC-2025-60High 7.5Upstreamlibexpat through 2.5.0 allows a denial of service (resource consumption) because many ful…JLSEC-2025-58High 7.5UpstreamIn libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a…JLSEC-2025-57High 8.1Upstreamlibexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.JLSEC-2025-56Critical 9.8UpstreamIn Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.JLSEC-2025-55High 7.5UpstreamIn Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.JLSEC-2025-54Medium 6.5UpstreamIn Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in `build_…JLSEC-2025-53Critical 9.8Upstreamxmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-sepa…JLSEC-2025-52Critical 9.8Upstream`xmltok_impl.c` in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding…JLSEC-2025-51High 7.5UpstreamExpat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.JLSEC-2025-50Critical 9.8UpstreamExpat (aka libexpat) before 2.4.4 has a signed integer overflow in `XML_GetBuffer`, for...JLSEC-2025-49High 8.8UpstreamstoreAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.JLSEC-2025-48High 8.8UpstreamnextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overfl…JLSEC-2025-47High 8.8Upstreamlookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.JLSEC-2025-46Critical 9.8UpstreamdefineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflo…JLSEC-2025-45Critical 9.8Upstream`build_model` in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.JLSEC-2025-44Critical 9.8UpstreamaddBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.JLSEC-2025-43High 7.8UpstreamIn doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exist…JLSEC-2025-42High 8.8UpstreamIn Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtt…JLSEC-2025-41High 7.5UpstreamIn libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD …