Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3783
HistoryMar 27, 2017 - 5:30 a.m.

Denial Of Service (DoS)

2017-03-2705:30:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.033 Low

EPSS

Percentile

91.3%

expat is vulnerable to denial of service (DoS) attacks, with the possibility of other attacks. The vulnerability exists because there are multiple integer overflows in the XML_GetBuffer function that leads to a heap-based buffer overflow which may lead to further unspecified impact. CVE-2016-4472 is related to the original issues CVE-2015-1283 and CVE-2015-2716, which were both incomplete due to the possibility of having the overflow checks optimized out during compilation.

CPENameOperatorVersion
expateq2.1
expateq2.1