ZeroHour

CVE-2021-45960

PoC ×2
CVSS 3.1
8.8 high
EPSS
4%p90
Published
()
Modified
Description

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

Vendors
libexpat projecttenabledebiansiemensnetapp
Products
libexpat, nessus, debian linux, sinema remote connect server, active iq unified manager, hci baseboard management controller, oncommand workflow automation, solidfire \& hci management node
Weakness
CWE-682
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.