Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12247
HistoryJan 15, 2019 - 9:14 a.m.

Denial Of Service (DoS) Or Arbitrary Code Execution

2019-01-1509:14:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.008 Low

EPSS

Percentile

81.9%

expat is vulnerable to denial of service (DoS) or arbitrary code execution attacks. When users input malformed document, expat XML parser mishandles the input which causes a buffer overflow during the processing and error reporting. This leading to a denial of service and conceivably result in remote code execution.

References