Known vulnerabilities in expat-devel

Vendor: OpenAnolis
Software: expat-devel
Software CPE: cpe:2.3:o:openanolis:expat-devel:*:*:*:*:*:anolis_os:*:*
Total vulnerabilities: 36
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting expat-devel expat-devel is affected by 36 known vulnerabilities: 18 high, 17 medium, 1 low Critical High Medium Low

Vulnerabilities (36)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144338 - Protection Mechanism Failure
CVE-2026-50219
CWE-693 Medium
No
No
2.5.0-14, 2.5.0-16 19.08.2026 SB2026081992
SB2026081995
SB2026081997
and 12 more
#VU144340 - Out-of-bounds write
CVE-2026-56132
CWE-787 High
No
No
2.5.0-17 19.08.2026 SB2026081992
SB2026081995
SB2026081997
and 6 more
#VU144341 - Integer overflow
CVE-2026-56403
CWE-190 Medium
No
No
2.5.0-18 19.08.2026 SB2026081992
SB2026081995
SB20260819116
and 4 more
#VU144343 - Integer overflow
CVE-2026-56405
CWE-190 Medium
No
No
2.5.0-16 19.08.2026 SB2026081992
SB2026081995
SB20260819116
and 4 more
#VU144344 - Integer overflow
CVE-2026-56406
CWE-190 Medium
No
No
2.5.0-16 19.08.2026 SB2026081992
SB2026081995
SB20260819116
and 4 more
#VU144350 - Protection Mechanism Failure
CVE-2026-56412
CWE-693 Medium
No
No
2.5.0-16 19.08.2026 SB2026081992
SB2026081995
SB2026081997
and 6 more
#VU124278 - NULL Pointer Dereference
CVE-2026-32778
CWE-476 Low
No
No
2.5.0-12 24.03.2026 SB2026032435
SB2026033028
SB2026033199
and 16 more
#VU124277 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-32777
CWE-835 Medium
No
No
2.5.0-11 24.03.2026 SB2026032435
SB2026032436
SB2026032437
and 24 more
#VU124274 - NULL Pointer Dereference
CVE-2026-32776
CWE-476 Medium
No
No
2.5.0-11 24.03.2026 SB2026032435
SB2026032765
SB2026033028
and 21 more
#VU122268 - Integer overflow
CVE-2026-25210
CWE-190 High
No
No
2.5.0-9 03.02.2026 SB2026020364
SB20260205121
SB2026020611
and 22 more
#VU122267 - NULL Pointer Dereference
CVE-2026-24515
CWE-476 Medium
No
No
2.5.0-9 03.02.2026 SB2026020364
SB2026020367
SB2026020368
and 18 more
#VU115751 - Resource exhaustion
CVE-2025-59375
CWE-400 Medium
No
No
2.5.0-1, 2.5.0-8 17.09.2025 SB2025091783
SB2025091789
SB2025091790
and 107 more
#VU105723 - Stack-based buffer overflow
CVE-2024-8176
CWE-121 High
No
No
2.2.5-17, 2.5.0-5 14.03.2025 SB2025031426
SB2025031429
SB2025031430
and 105 more
#VU99614 - Improper input validation
CVE-2024-50602
CWE-20 Medium
No
No
2.2.5-16, 2.5.0-4 01.11.2024 SB2024110155
SB2024110182
SB2024110534
and 98 more
#VU96899 - Integer overflow
CVE-2024-45492
CWE-190 High
No
No
2.2.5-13.0.1, 2.5.0-4 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 108 more
#VU96898 - Integer overflow
CVE-2024-45491
CWE-190 High
No
No
2.2.5-13.0.1, 2.5.0-4 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 106 more
#VU96897 - Buffer Underwrite ('Buffer Underflow')
CVE-2024-45490
CWE-124 High
No
No
2.2.5-13.0.1, 2.5.0-4 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 113 more
#VU87337 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2024-28757
CWE-611 Medium
No
No
2.5.0-4 11.03.2024 SB2024031135
SB2024031143
SB2024031144
and 74 more
#VU86231 - Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
CVE-2023-52426
CWE-776 Medium
No
No
2.5.0-6 07.02.2024 SB2024020750
SB2024020754
SB2024020765
and 23 more
#VU86230 - Resource exhaustion
CVE-2023-52425
CWE-400 Medium
No
No
2.2.5-13, 2.5.0-3 07.02.2024 SB2024020750
SB2024020754
SB2024020765
and 120 more


Showing elements 1 - 20 out of 36