libexpat
cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*
- < 2.7.4
A vulnerability exists in libexpat versions prior to 2.7.4, where the doContent function improperly calculates the buffer size due to a lack of integer overflow checks during tag buffer reallocation. This oversight can lead to memory allocation errors or potential exploitation.
The vulnerability allows for integer overflow, which can be exploited to cause memory allocation errors or potentially manipulate memory in a way that could be exploited.
Users can upgrade to libexpat version 2.7.4 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.