Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.

Expat_jll

JLSEC-2026-384No summary availableJLSEC-2026-383No summary availableJLSEC-2026-382No summary availableJLSEC-2026-381No summary availableJLSEC-2026-380No summary availableJLSEC-2026-379No summary availableJLSEC-2026-378No summary availableJLSEC-2025-173libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocatio…JLSEC-2025-65An issue was discovered in libexpat before 2.6.4JLSEC-2025-64An issue was discovered in libexpat before 2.6.3JLSEC-2025-63An issue was discovered in libexpat before 2.6.3JLSEC-2025-62An issue was discovered in libexpat before 2.6.3JLSEC-2025-61libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use o…JLSEC-2025-59libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at c…JLSEC-2025-60libexpat through 2.5.0 allows a denial of service (resource consumption) because many ful…JLSEC-2025-58In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a…JLSEC-2025-57libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.JLSEC-2025-56In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.JLSEC-2025-55In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.JLSEC-2025-54In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_m…JLSEC-2025-53xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-sepa…JLSEC-2025-52xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, …JLSEC-2025-51Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.JLSEC-2025-50Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for con…JLSEC-2025-49storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.JLSEC-2025-48nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overfl…JLSEC-2025-47lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.JLSEC-2025-46defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflo…JLSEC-2025-45build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.JLSEC-2025-44addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.JLSEC-2025-43In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exist…JLSEC-2025-42In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtt…JLSEC-2025-41In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD …