Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2022-43680
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.002
EPSS Ranking
48.0%
CVSS Severity
CVSS v3 Score
7.5
References
http://www.openwall.com/lists/oss-security/2023/12/28/5
http://www.openwall.com/lists/oss-security/2024/01/03/5
https://github.com/libexpat/libexpat/issues/649
https://github.com/libexpat/libexpat/pull/616
https://github.com/libexpat/libexpat/pull/650
https://lists.debian.org/debian-lts-announce/2022/10/msg00033.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJ5VY2VYXE4WTRGQ6LMGLF6FV3SY37YE/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BY4OPSIB33ETNUXZY2UPZ4NGQ3OKDY4D/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPQVIF6TOJNY2T3ZZETFKR4G34FFREBQ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFCOMBSOJKLIKCGCJWHLJXO4EVYBG7AR/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUJ2BULJTZ2BMSKQHB6US674P55UCWWS/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XG5XOOB7CD55CEE6OJYKSACSIMQ4RWQ6/
https://security.gentoo.org/glsa/202210-38
https://security.netapp.com/advisory/ntap-20221118-0007/
https://www.debian.org/security/2022/dsa-5266
http://www.openwall.com/lists/oss-security/2023/12/28/5
http://www.openwall.com/lists/oss-security/2024/01/03/5
https://github.com/libexpat/libexpat/issues/649
https://github.com/libexpat/libexpat/pull/616
https://github.com/libexpat/libexpat/pull/650
https://lists.debian.org/debian-lts-announce/2022/10/msg00033.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJ5VY2VYXE4WTRGQ6LMGLF6FV3SY37YE/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BY4OPSIB33ETNUXZY2UPZ4NGQ3OKDY4D/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPQVIF6TOJNY2T3ZZETFKR4G34FFREBQ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFCOMBSOJKLIKCGCJWHLJXO4EVYBG7AR/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUJ2BULJTZ2BMSKQHB6US674P55UCWWS/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XG5XOOB7CD55CEE6OJYKSACSIMQ4RWQ6/
https://security.gentoo.org/glsa/202210-38
https://security.netapp.com/advisory/ntap-20221118-0007/
https://www.debian.org/security/2022/dsa-5266
Products affected by CVE-2022-43680
Libexpat Project
»
Libexpat
»
Version:
N/A
cpe:2.3:a:libexpat_project:libexpat:-
Libexpat Project
»
Libexpat
»
Version:
1.95.0
cpe:2.3:a:libexpat_project:libexpat:1.95.0
Libexpat Project
»
Libexpat
»
Version:
1.95.1
cpe:2.3:a:libexpat_project:libexpat:1.95.1
Libexpat Project
»
Libexpat
»
Version:
1.95.2
cpe:2.3:a:libexpat_project:libexpat:1.95.2
Libexpat Project
»
Libexpat
»
Version:
1.95.3
cpe:2.3:a:libexpat_project:libexpat:1.95.3
Libexpat Project
»
Libexpat
»
Version:
1.95.4
cpe:2.3:a:libexpat_project:libexpat:1.95.4
Libexpat Project
»
Libexpat
»
Version:
1.95.5
cpe:2.3:a:libexpat_project:libexpat:1.95.5
Libexpat Project
»
Libexpat
»
Version:
1.95.6
cpe:2.3:a:libexpat_project:libexpat:1.95.6
Libexpat Project
»
Libexpat
»
Version:
1.95.7
cpe:2.3:a:libexpat_project:libexpat:1.95.7
Libexpat Project
»
Libexpat
»
Version:
1.95.8
cpe:2.3:a:libexpat_project:libexpat:1.95.8
Libexpat Project
»
Libexpat
»
Version:
2.0.0
cpe:2.3:a:libexpat_project:libexpat:2.0.0
Libexpat Project
»
Libexpat
»
Version:
2.0.1
cpe:2.3:a:libexpat_project:libexpat:2.0.1
Libexpat Project
»
Libexpat
»
Version:
2.1.0
cpe:2.3:a:libexpat_project:libexpat:2.1.0
Libexpat Project
»
Libexpat
»
Version:
2.1.1
cpe:2.3:a:libexpat_project:libexpat:2.1.1
Libexpat Project
»
Libexpat
»
Version:
2.2.0
cpe:2.3:a:libexpat_project:libexpat:2.2.0
Libexpat Project
»
Libexpat
»
Version:
2.2.1
cpe:2.3:a:libexpat_project:libexpat:2.2.1
Libexpat Project
»
Libexpat
»
Version:
2.2.10
cpe:2.3:a:libexpat_project:libexpat:2.2.10
Libexpat Project
»
Libexpat
»
Version:
2.2.2
cpe:2.3:a:libexpat_project:libexpat:2.2.2
Libexpat Project
»
Libexpat
»
Version:
2.2.3
cpe:2.3:a:libexpat_project:libexpat:2.2.3
Libexpat Project
»
Libexpat
»
Version:
2.2.4
cpe:2.3:a:libexpat_project:libexpat:2.2.4
Libexpat Project
»
Libexpat
»
Version:
2.2.5
cpe:2.3:a:libexpat_project:libexpat:2.2.5
Libexpat Project
»
Libexpat
»
Version:
2.2.6
cpe:2.3:a:libexpat_project:libexpat:2.2.6
Libexpat Project
»
Libexpat
»
Version:
2.2.7
cpe:2.3:a:libexpat_project:libexpat:2.2.7
Libexpat Project
»
Libexpat
»
Version:
2.2.8
cpe:2.3:a:libexpat_project:libexpat:2.2.8
Libexpat Project
»
Libexpat
»
Version:
2.2.9
cpe:2.3:a:libexpat_project:libexpat:2.2.9
Libexpat Project
»
Libexpat
»
Version:
2.3.0
cpe:2.3:a:libexpat_project:libexpat:2.3.0
Libexpat Project
»
Libexpat
»
Version:
2.4.0
cpe:2.3:a:libexpat_project:libexpat:2.4.0
Libexpat Project
»
Libexpat
»
Version:
2.4.1
cpe:2.3:a:libexpat_project:libexpat:2.4.1
Libexpat Project
»
Libexpat
»
Version:
2.4.3
cpe:2.3:a:libexpat_project:libexpat:2.4.3
Libexpat Project
»
Libexpat
»
Version:
2.4.4
cpe:2.3:a:libexpat_project:libexpat:2.4.4
Libexpat Project
»
Libexpat
»
Version:
2.4.5
cpe:2.3:a:libexpat_project:libexpat:2.4.5
Libexpat Project
»
Libexpat
»
Version:
2.4.6
cpe:2.3:a:libexpat_project:libexpat:2.4.6
Libexpat Project
»
Libexpat
»
Version:
2.4.7
cpe:2.3:a:libexpat_project:libexpat:2.4.7
Libexpat Project
»
Libexpat
»
Version:
2.4.8
cpe:2.3:a:libexpat_project:libexpat:2.4.8
Libexpat Project
»
Libexpat
»
Version:
2.4.9
cpe:2.3:a:libexpat_project:libexpat:2.4.9
Netapp
»
Active Iq Unified Manager
»
Version:
N/A
cpe:2.3:a:netapp:active_iq_unified_manager:-
Netapp
»
Oncommand Workflow Automation
»
Version:
N/A
cpe:2.3:a:netapp:oncommand_workflow_automation:-
Netapp
»
Solidfire & Hci Management Node
»
Version:
N/A
cpe:2.3:a:netapp:solidfire_&_hci_management_node:-
Netapp
»
H300s
»
Version:
N/A
cpe:2.3:h:netapp:h300s:-
Netapp
»
H410c
»
Version:
N/A
cpe:2.3:h:netapp:h410c:-
Netapp
»
H410s
»
Version:
N/A
cpe:2.3:h:netapp:h410s:-
Netapp
»
H500s
»
Version:
N/A
cpe:2.3:h:netapp:h500s:-
Netapp
»
H700s
»
Version:
N/A
cpe:2.3:h:netapp:h700s:-
Netapp
»
Hci Compute Node
»
Version:
N/A
cpe:2.3:h:netapp:hci_compute_node:-
Debian
»
Debian Linux
»
Version:
10.0
cpe:2.3:o:debian:debian_linux:10.0
Debian
»
Debian Linux
»
Version:
11.0
cpe:2.3:o:debian:debian_linux:11.0
Fedoraproject
»
Fedora
»
Version:
35
cpe:2.3:o:fedoraproject:fedora:35
Fedoraproject
»
Fedora
»
Version:
36
cpe:2.3:o:fedoraproject:fedora:36
Fedoraproject
»
Fedora
»
Version:
37
cpe:2.3:o:fedoraproject:fedora:37
Netapp
»
H300s Firmware
»
Version:
N/A
cpe:2.3:o:netapp:h300s_firmware:-
Netapp
»
H410c Firmware
»
Version:
N/A
cpe:2.3:o:netapp:h410c_firmware:-
Netapp
»
H410s Firmware
»
Version:
N/A
cpe:2.3:o:netapp:h410s_firmware:-
Netapp
»
H500s Firmware
»
Version:
N/A
cpe:2.3:o:netapp:h500s_firmware:-
Netapp
»
H700s Firmware
»
Version:
N/A
cpe:2.3:o:netapp:h700s_firmware:-
Netapp
»
Hci Compute Node Firmware
»
Version:
N/A
cpe:2.3:o:netapp:hci_compute_node_firmware:-
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved