← Back to browse
·
API
CVE-2022-22824
Severity
CRITICAL
CVSS
9.8
EPSS
0.03404
Risk score
40.39
CISA KEV
No
PoC
No
Published
2022-01-08
Modified
2025-05-05
First seen
2026-08-07
Aliases
EUVD-2022-27962, GHSA-5PJ8-9WMW-J96M
Products
n/a:n/a n/a
Sources
euvd
EUVD-2022-27962
Description
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
References
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-27962
https://github.com/libexpat/libexpat/pull/539
http://www.openwall.com/lists/oss-security/2022/01/17/3
https://www.tenable.com/security/tns-2022-05
https://www.debian.org/security/2022/dsa-5073
https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
https://security.gentoo.org/glsa/202209-24