Expat是一款使用C语言编写的快速流式XML解析器。 Expat 2.0.1版本的libexpat模块中存在安全漏洞。当Expat在 Python,、PyXML、 w3c-libwww和其他软件中运行时,攻击者可以将包含UTF-8字符序列的特制XML文档作为libexpat模块中lib/xmltok_impl.c的updatePosition函数参数以触发buffer over-read,造成拒绝服务(应用程序崩溃)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2009-3031 | Symantec Altiris Product ActiveX控件栈溢出漏洞 | |
| CVE-2009-3298 | Mahara 权限提升漏洞 | |
| CVE-2009-3299 | Mahara "resume blocktype" 跨站脚本漏洞 | |
| CVE-2009-3851 | Sun Solaris JDS ’xscreensaver(1)’本地信息泄露漏洞 | |
| CVE-2009-3852 | IBM Runtimes for Java Technology XML组件未明漏洞 |
No comments yet