Libexpat

Vendor:

First CVE: Nov 3, 2009 · Active for 16 years

61
Total CVEs
More Total CVEs than 98% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Libexpat over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 3, 2009
16 years ago
Most Recent CVE
Jun 21, 2026
33 days ago

CVE Severity & Scoring

Libexpat61 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local21 (34.4%)
Network33 (54.1%)
Unknown7 (11.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (63.9%)
High15 (24.6%)
Unknown7 (11.5%)
User Interaction
None47 (77.0%)
Unknown7 (11.5%)
Required7 (11.5%)
Privileges Required
Low7 (11.5%)
High0 (0.0%)
None47 (77.0%)
Unknown7 (11.5%)

Top CVEs

Signals from CVEs in this product scope (61 CVEs).

61 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
Feb 16, 20229.850NONO
In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
May 10, 20267.535NONO
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
Jan 24, 20229.835NONO
The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a
Nov 3, 20095.035NONO
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute
Jun 30, 20168.134NONO
In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sha
Jun 19, 20266.933NONO
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
Feb 18, 20229.833NONO
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
Feb 16, 20229.833NONO
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Jan 10, 20229.833NONO
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
Jan 10, 20229.833NONO

Exploit Exposure

Signals from CVEs in this product scope (61 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (61 CVEs).

Media Mentions

Signals from CVEs in this product scope (61 CVEs).

Top CNAs Publishing CVEs For Libexpat

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.2.217.80.5%00
2.2.117.80.5%00
2.0.125.026.1%00
2.0.024.73.1%00
1.95.824.73.1%00
1.95.724.73.1%00
1.95.624.73.1%00
1.95.524.73.1%00
1.95.424.73.1%00
1.95.224.73.1%00
1.95.124.73.1%00