Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
|
Configuration 9 (hide)
|
Configuration 10 (hide)
|
Configuration 11 (hide)
|
History
12 Feb 2023, 23:15
Type | Values Removed | Values Added |
---|---|---|
Summary | Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow. | |
References |
|
02 Feb 2023, 21:16
Type | Values Removed | Values Added |
---|---|---|
Summary | An out-of-bounds read flaw was found in the way Expat processed certain input. A remote attacker could send specially crafted XML that, when parsed by an application using the Expat library, would cause that application to crash or, possibly, execute arbitrary code with the permission of the user running the application. | |
References |
|
27 Jun 2022, 17:05
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
First Time |
Python
Python python Mcafee policy Auditor Mcafee |
|
CPE | cpe:2.3:o:suse:linux_enterprise_desktop:12.0:sp1:*:*:*:*:*:* cpe:2.3:o:suse:linux_enterprise_desktop:12:*:*:*:*:*:*:* cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:*:*:*:*:*:*:* cpe:2.3:o:suse:linux_enterprise_server:12:*:*:*:*:*:*:* cpe:2.3:o:suse:linux_enterprise_server:12.0:sp1:*:*:*:*:*:* |
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:* cpe:2.3:o:suse:linux_enterprise_desktop:12:sp1:*:*:*:*:*:* cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp1:*:*:*:*:*:* cpe:2.3:o:suse:linux_enterprise_server:12:sp1:*:*:*:*:*:* cpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:* cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:-:*:*:*:*:*:* cpe:2.3:a:mcafee:policy_auditor:*:*:*:*:*:*:*:* |
25 Jan 2021, 15:44
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* |
Information
Published : 2016-05-26 16:59
Updated : 2023-02-12 23:15
NVD link : CVE-2016-0718
Mitre link : CVE-2016-0718
JSON object : View
Products Affected
opensuse
- leap
- opensuse
apple
- mac_os_x
libexpat_project
- libexpat
python
- python
suse
- linux_enterprise_server
- linux_enterprise_debuginfo
- linux_enterprise_desktop
- linux_enterprise_software_development_kit
- studio_onsite
mcafee
- policy_auditor
debian
- debian_linux
canonical
- ubuntu_linux
mozilla
- firefox
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer