CVE-2021-45960
HIGH 9.0EPSS 4.2%
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 4.23% chance of exploitation in the next 30 days, 90th percentile
- Published
- 2022-01-01
- Updated
- 2025-05-05
Proof-of-concept exploits (2)
- Trinadh465/external_lib_AOSP10_r33_CVE-2021-45960_CVE-2021-46143-0★ · 2022-05-25
- nanopathi/external_expat_AOSP10_r33_CVE-2021-459600★ · 2022-04-11